Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5419

Опубликовано: 29 апр. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gnutlsOut of support scope
Red Hat Enterprise Linux 7gnutlsNot affected
Red Hat Enterprise Linux 8gnutlsFix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-hypershift-rhel9Under investigation
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Fix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Fix deferred
Red Hat Enterprise Linux 10gnutlsFixedRHSA-2026:2061326.05.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportgnutlsFixedRHSA-2026:2640916.06.2026
Red Hat Enterprise Linux 9gnutlsFixedRHSA-2026:2061226.05.2026
Red Hat Enterprise Linux 9gnutlsFixedRHSA-2026:2061226.05.2026

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-208
https://bugzilla.redhat.com/show_bug.cgi?id=2467686gnutls: gnutls: Information disclosure via timing side-channel in PKCS#7 padding removal

EPSS

Процентиль: 31%
0.00379
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
4 месяца назад

A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.

CVSS3: 3.7
nvd
4 месяца назад

A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.

CVSS3: 3.7
msrc
3 месяца назад

Guntls: gnutls: information disclosure via timing side-channel in pkcs#7 padding removal

CVSS3: 3.7
debian
4 месяца назад

A flaw was found in gnutls. The PKCS#7 padding check, performed during ...

CVSS3: 3.7
redos
3 месяца назад

Уязвимость gnutls

EPSS

Процентиль: 31%
0.00379
Низкий

3.7 Low

CVSS3