Описание
A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | gnutls | Out of support scope | ||
| Red Hat Enterprise Linux 7 | gnutls | Not affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-hypershift-rhel9 | Under investigation | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Affected | ||
| Red Hat Enterprise Linux 10 | gnutls | Fixed | RHSA-2026:20613 | 26.05.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | gnutls | Fixed | RHSA-2026:26409 | 16.06.2026 |
| Red Hat Enterprise Linux 8 | gnutls | Fixed | RHSA-2026:20611 | 26.05.2026 |
| Red Hat Enterprise Linux 8 | gnutls | Fixed | RHSA-2026:20611 | 26.05.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | gnutls | Fixed | RHSA-2026:33125 | 29.06.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | libtasn1 | Fixed | RHSA-2026:33125 | 29.06.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.2 High
CVSS3
Связанные уязвимости
A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.
A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.
Gnutls: gnutls: information disclosure via heap overread in rsa key exchange
A flaw was found in libgnutls. A remote attacker, by sending an extrem ...
A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.
EPSS
8.2 High
CVSS3