Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5419

Опубликовано: 29 апр. 2026
Источник: redhat
CVSS3: 3.7

Описание

A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gnutlsOut of support scope
Red Hat Enterprise Linux 7gnutlsNot affected
Red Hat Enterprise Linux 8gnutlsFix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-hypershift-rhel9Under investigation
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Enterprise Linux 10gnutlsFixedRHSA-2026:2061326.05.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportgnutlsFixedRHSA-2026:2640916.06.2026
Red Hat Enterprise Linux 9gnutlsFixedRHSA-2026:2061226.05.2026
Red Hat Enterprise Linux 9gnutlsFixedRHSA-2026:2061226.05.2026
Red Hat Enterprise Linux 9.4 Update Services for SAP SolutionsgnutlsFixedRHSA-2026:3296229.06.2026

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-208
https://bugzilla.redhat.com/show_bug.cgi?id=2467686gnutls: gnutls: Information disclosure via timing side-channel in PKCS#7 padding removal

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 2 месяцев назад

A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.

CVSS3: 3.7
nvd
около 2 месяцев назад

A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.

CVSS3: 3.7
msrc
около 2 месяцев назад

Guntls: gnutls: information disclosure via timing side-channel in pkcs#7 padding removal

CVSS3: 3.7
debian
около 2 месяцев назад

A flaw was found in gnutls. The PKCS#7 padding check, performed during ...

CVSS3: 3.7
github
около 2 месяцев назад

A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.

3.7 Low

CVSS3