Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-33845

Опубликовано: 30 апр. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 7.5

Описание

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.

РелизСтатусПримечание
devel

not-affected

3.8.12-2ubuntu1.1
esm-infra-legacy/xenial

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

released

3.6.13-2ubuntu1.12+esm2
esm-infra/xenial

ignored

end of ESM support, was needs-triage
fips-preview/jammy

needed

fips-updates/jammy

released

3.7.3-4ubuntu1.9+Fips1
fips-updates/noble

released

3.8.3-1.1ubuntu3.6+Fips1.2
jammy

released

3.7.3-4ubuntu1.9
noble

released

3.8.3-1.1ubuntu3.6

Показывать по

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
5 месяцев назад

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.

CVSS3: 7.5
nvd
5 месяцев назад

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.

CVSS3: 8.2
msrc
4 месяца назад

Gnutls: gnutls: denial of service via dtls zero-length fragment

CVSS3: 7.5
debian
5 месяцев назад

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments wit ...

CVSS3: 9.1
redos
3 месяца назад

Уязвимость gnutls

7.5 High

CVSS3