Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5260

Опубликовано: 29 апр. 2026
Источник: redhat
CVSS3: 8.2

Описание

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gnutlsOut of support scope
Red Hat Enterprise Linux 7gnutlsNot affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Affected
Red Hat Enterprise Linux 10gnutlsFixedRHSA-2026:2061326.05.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportgnutlsFixedRHSA-2026:2640916.06.2026
Red Hat Enterprise Linux 8gnutlsFixedRHSA-2026:2061126.05.2026
Red Hat Enterprise Linux 8gnutlsFixedRHSA-2026:2061126.05.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportgnutlsFixedRHSA-2026:3312529.06.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportlibtasn1FixedRHSA-2026:3312529.06.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-126
https://bugzilla.redhat.com/show_bug.cgi?id=2467450gnutls: gnutls: Information disclosure via heap overread in RSA key exchange

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
ubuntu
4 месяца назад

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.

CVSS3: 8.2
nvd
4 месяца назад

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.

CVSS3: 8.2
msrc
4 месяца назад

Gnutls: gnutls: information disclosure via heap overread in rsa key exchange

CVSS3: 8.2
debian
4 месяца назад

A flaw was found in libgnutls. A remote attacker, by sending an extrem ...

CVSS3: 8.2
redos
3 месяца назад

Уязвимость gnutls

8.2 High

CVSS3