Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:2115-1

Опубликовано: 29 мая 2026
Источник: suse-cvrf

Описание

Security update for gnutls

This update for gnutls fixes the following issues

  • CVE-2026-3833: x509/name-constraints: compare domain names case-insensitive (bsc#1263707).
  • CVE-2026-5260: lib/pkcs11_privkey: guard against overreading on short ciphertexts (bsc#1263715).
  • CVE-2026-5419: gnutls_cipher_decrypt3: make PKCS#7 unpadding branch free (bsc#1263716).
  • CVE-2026-33845: buffers: switch from end_offset over to frag_length (bsc#1263704).
  • CVE-2026-33846: buffers: add more checks to DTLS reassembly (bsc#1263705).
  • CVE-2026-42009: lib/buffers: ensure packets have differing sequence numbers (bsc#1263708).
  • CVE-2026-42010: lib/auth/rsa_psk: fix binary PSK identity lookup (bsc#1263709).
  • CVE-2026-42011: x509/name_constraints: fix intersecting empty constraints (bsc#1263710).
  • CVE-2026-42012: x509/hostname-verify: make URI/SRV SAN preclude CN fallback (bsc#1263711).
  • CVE-2026-42013: x509: prevent fallback on oversized SAN (bsc#1263712).
  • CVE-2026-42014: pkcs11_write: fix UAF and leak in gnutls_pkcs11_token_set_pin (bsc#1263713).
  • CVE-2026-42015: x509/pkcs12_bag: fix off-by-one in bag element bounds chec (bsc#1263714).

Список пакетов

Container bci/php-apache:latest
libgnutls30-3.8.3-150600.4.20.1
Container bci/php-fpm:latest
libgnutls30-3.8.3-150600.4.20.1
Container bci/php:latest
libgnutls30-3.8.3-150600.4.20.1
Container bci/spack:latest
libgnutls30-3.8.3-150600.4.20.1
Container suse/kiosk/firefox-esr:latest
libgnutls30-3.8.3-150600.4.20.1
Container suse/manager/5.0/x86_64/server:latest
libgnutls30-3.8.3-150600.4.20.1
Container suse/samba-client:latest
libgnutls30-3.8.3-150600.4.20.1
Container suse/samba-server:latest
libgnutls30-3.8.3-150600.4.20.1
Container suse/samba-toolbox:latest
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-Azure-3P
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-Azure-Basic
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-Azure-Standard
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-BYOS
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-BYOS-Azure
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-BYOS-EC2
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-BYOS-GCE
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-CHOST-BYOS
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-CHOST-BYOS-Aliyun
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-CHOST-BYOS-Azure
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-CHOST-BYOS-EC2
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-CHOST-BYOS-GCE
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-CHOST-BYOS-GDC
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-CHOST-BYOS-SAP-CCloud
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-EC2
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-EC2-ECS-HVM
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-GCE
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-HPC
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-HPC-Azure
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-HPC-BYOS
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-HPC-BYOS-Azure
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-HPC-BYOS-EC2
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-HPC-BYOS-GCE
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-HPC-EC2
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-HPC-GCE
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-Hardened-BYOS
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-Hardened-BYOS-Azure
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-Hardened-BYOS-EC2
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-Hardened-BYOS-GCE
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-SAP
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-SAP-Azure
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-SAP-Azure-3P
gnutls-3.8.3-150600.4.20.1
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-SAP-BYOS
gnutls-3.8.3-150600.4.20.1
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-SAP-BYOS-Azure
gnutls-3.8.3-150600.4.20.1
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-SAP-BYOS-EC2
gnutls-3.8.3-150600.4.20.1
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-SAP-BYOS-GCE
gnutls-3.8.3-150600.4.20.1
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-SAP-EC2
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-SAP-GCE
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-SAP-Hardened
gnutls-3.8.3-150600.4.20.1
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-SAP-Hardened-Azure
gnutls-3.8.3-150600.4.20.1
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-SAP-Hardened-BYOS
gnutls-3.8.3-150600.4.20.1
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-SAP-Hardened-BYOS-Azure
gnutls-3.8.3-150600.4.20.1
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-SAP-Hardened-BYOS-EC2
gnutls-3.8.3-150600.4.20.1
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-SAP-Hardened-BYOS-GCE
gnutls-3.8.3-150600.4.20.1
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-SAP-Hardened-EC2
gnutls-3.8.3-150600.4.20.1
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-SAP-Hardened-GCE
gnutls-3.8.3-150600.4.20.1
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-SAPCAL
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-SAPCAL-Azure
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-SAPCAL-EC2
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP6-SAPCAL-GCE
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-Azure-3P
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-Azure-Basic
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-Azure-Standard
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-BYOS-Azure
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-BYOS-EC2
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-BYOS-GCE
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-CHOST-BYOS-Aliyun
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-CHOST-BYOS-Azure
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-CHOST-BYOS-EC2
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-CHOST-BYOS-GCE
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-CHOST-BYOS-GDC
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-CHOST-BYOS-SAP-CCloud
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-EC2
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-EC2-ECS-HVM
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-GCE
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-HPC-Azure
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-HPC-BYOS-Azure
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-HPC-BYOS-EC2
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-HPC-BYOS-GCE
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-Hardened-BYOS-Azure
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-Hardened-BYOS-EC2
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-Hardened-BYOS-GCE
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-SAP-Azure
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-SAP-Azure-3P
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-SAP-BYOS-Azure
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-SAP-BYOS-EC2
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-SAP-BYOS-GCE
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-SAP-EC2
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-SAP-GCE
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-SAP-Hardened-Azure
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-SAP-Hardened-BYOS-Azure
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-SAP-Hardened-BYOS-EC2
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-SAP-Hardened-BYOS-GCE
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-SAP-Hardened-GCE
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-SAPCAL-Azure
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-SAPCAL-EC2
libgnutls30-3.8.3-150600.4.20.1
Image SLES15-SP7-SAPCAL-GCE
libgnutls30-3.8.3-150600.4.20.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
gnutls-3.8.3-150600.4.20.1
libgnutls-devel-3.8.3-150600.4.20.1
libgnutls30-3.8.3-150600.4.20.1
libgnutls30-32bit-3.8.3-150600.4.20.1
libgnutlsxx-devel-3.8.3-150600.4.20.1
libgnutlsxx30-3.8.3-150600.4.20.1
SUSE Linux Enterprise Server 15 SP6-LTSS
gnutls-3.8.3-150600.4.20.1
libgnutls-devel-3.8.3-150600.4.20.1
libgnutls30-3.8.3-150600.4.20.1
libgnutls30-32bit-3.8.3-150600.4.20.1
libgnutlsxx-devel-3.8.3-150600.4.20.1
libgnutlsxx30-3.8.3-150600.4.20.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6
gnutls-3.8.3-150600.4.20.1
libgnutls-devel-3.8.3-150600.4.20.1
libgnutls30-3.8.3-150600.4.20.1
libgnutls30-32bit-3.8.3-150600.4.20.1
libgnutlsxx-devel-3.8.3-150600.4.20.1
libgnutlsxx30-3.8.3-150600.4.20.1

Описание

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.


Затронутые продукты
Container bci/php-apache:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/php-fpm:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/php:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/spack:latest:libgnutls30-3.8.3-150600.4.20.1

Ссылки

Описание

A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.


Затронутые продукты
Container bci/php-apache:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/php-fpm:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/php:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/spack:latest:libgnutls30-3.8.3-150600.4.20.1

Ссылки

Описание

A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.


Затронутые продукты
Container bci/php-apache:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/php-fpm:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/php:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/spack:latest:libgnutls30-3.8.3-150600.4.20.1

Ссылки

Описание

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.


Затронутые продукты
Container bci/php-apache:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/php-fpm:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/php:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/spack:latest:libgnutls30-3.8.3-150600.4.20.1

Ссылки

Описание

A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest-Shamir-Adleman - Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.


Затронутые продукты
Container bci/php-apache:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/php-fpm:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/php:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/spack:latest:libgnutls30-3.8.3-150600.4.20.1

Ссылки

Описание

A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems.


Затронутые продукты
Container bci/php-apache:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/php-fpm:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/php:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/spack:latest:libgnutls30-3.8.3-150600.4.20.1

Ссылки

Описание

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.


Затронутые продукты
Container bci/php-apache:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/php-fpm:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/php:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/spack:latest:libgnutls30-3.8.3-150600.4.20.1

Ссылки

Описание

A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks.


Затронутые продукты
Container bci/php-apache:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/php-fpm:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/php:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/spack:latest:libgnutls30-3.8.3-150600.4.20.1

Ссылки

Описание

A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.


Затронутые продукты
Container bci/php-apache:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/php-fpm:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/php:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/spack:latest:libgnutls30-3.8.3-150600.4.20.1

Ссылки

Описание

A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts.


Затронутые продукты
Container bci/php-apache:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/php-fpm:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/php:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/spack:latest:libgnutls30-3.8.3-150600.4.20.1

Ссылки

Описание

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.


Затронутые продукты
Container bci/php-apache:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/php-fpm:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/php:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/spack:latest:libgnutls30-3.8.3-150600.4.20.1

Ссылки

Описание

A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.


Затронутые продукты
Container bci/php-apache:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/php-fpm:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/php:latest:libgnutls30-3.8.3-150600.4.20.1
Container bci/spack:latest:libgnutls30-3.8.3-150600.4.20.1

Ссылки
Уязвимость SUSE-SU-2026:2115-1