Описание
A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | gnutls | Out of support scope | ||
| Red Hat Enterprise Linux 7 | gnutls | Not affected | ||
| Red Hat Enterprise Linux 8 | gnutls | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-hypershift-rhel9 | Under investigation | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Fix deferred | ||
| Red Hat Enterprise Linux 10 | gnutls | Fixed | RHSA-2026:20613 | 26.05.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | gnutls | Fixed | RHSA-2026:26409 | 16.06.2026 |
| Red Hat Enterprise Linux 9 | gnutls | Fixed | RHSA-2026:20612 | 26.05.2026 |
| Red Hat Enterprise Linux 9 | gnutls | Fixed | RHSA-2026:20612 | 26.05.2026 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | gnutls | Fixed | RHSA-2026:32962 | 29.06.2026 |
Показывать по
Дополнительная информация
Статус:
3.7 Low
CVSS3
Связанные уязвимости
A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.
A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.
Guntls: gnutls: information disclosure via timing side-channel in pkcs#7 padding removal
A flaw was found in gnutls. The PKCS#7 padding check, performed during ...
A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.
3.7 Low
CVSS3