Описание
Important: gnutls security update
The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS.
Security Fix(es):
- gnutls: Fix qsort comparator in DTLS reassembly (CVE-2026-42009)
- gnutls: Fix crashing on an underflow with a DTLS datagram (CVE-2026-33845)
- gnutls: Fix RSA-PSK identity truncation (CVE-2026-42010)
- gnutls: Fix case-sensitivity of domain name comparison in name constraints (CVE-2026-3833)
- gnutls: Fix intersecting empty name constraints (CVE-2026-42011)
- gnutls: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly (CVE-2026-33846)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Затронутые продукты
Rocky Linux 9
Ссылки на источники
Исправления
- Red Hat - 2445762
- Red Hat - 2445763
- Red Hat - 2450624
- Red Hat - 2450625
- Red Hat - 2467279
- Red Hat - 2467289
- Red Hat - 2467437
- Red Hat - 2467441
- Red Hat - 2467448
- Red Hat - 2467450
- Red Hat - 2467451
- Red Hat - 2467678
- Red Hat - 2467686