Количество 20
Количество 20
GHSA-qcj7-gqxf-2cqq
A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.
CVE-2026-33846
A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.
CVE-2026-33846
A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.
CVE-2026-33846
A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.
CVE-2026-33846
Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassembly
CVE-2026-33846
A heap buffer overflow vulnerability exists in the DTLS handshake frag ...
BDU:2026-09344
Уязвимость функции merge_handshake_packet() криптографической библиотеки GnuTLS, позволяющая нарушителю вызвать отказ в обслуживании
ROS-20260625-73-0002
Уязвимость gnutls
SUSE-SU-2026:2366-1
Security update for gnutls
SUSE-SU-2026:2367-1
Security update for gnutls
SUSE-SU-2026:2087-1
Security update for gnutls
RLSA-2026:20611
Important: gnutls security update
ELSA-2026-20611
ELSA-2026-20611: gnutls security update (IMPORTANT)
SUSE-SU-2026:2115-1
Security update for gnutls
openSUSE-SU-2026:20778-1
Security update for gnutls
RLSA-2026:20613
Important: gnutls security update
RLSA-2026:20612
Important: gnutls security update
ELSA-2026-50346
ELSA-2026-50346: gnutls security fix update (IMPORTANT)
ELSA-2026-20613
ELSA-2026-20613: gnutls security update (IMPORTANT)
ELSA-2026-20612
ELSA-2026-20612: gnutls security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-qcj7-gqxf-2cqq A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption. | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-33846 A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption. | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-33846 A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption. | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-33846 A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption. | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-33846 Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassembly | CVSS3: 7.5 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-33846 A heap buffer overflow vulnerability exists in the DTLS handshake frag ... | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
BDU:2026-09344 Уязвимость функции merge_handshake_packet() криптографической библиотеки GnuTLS, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 1% Низкий | 5 месяцев назад | |
ROS-20260625-73-0002 Уязвимость gnutls | CVSS3: 7.5 | 1% Низкий | около 1 месяца назад | |
SUSE-SU-2026:2366-1 Security update for gnutls | около 2 месяцев назад | |||
SUSE-SU-2026:2367-1 Security update for gnutls | около 2 месяцев назад | |||
SUSE-SU-2026:2087-1 Security update for gnutls | 2 месяца назад | |||
RLSA-2026:20611 Important: gnutls security update | 2 месяца назад | |||
ELSA-2026-20611 ELSA-2026-20611: gnutls security update (IMPORTANT) | 2 месяца назад | |||
SUSE-SU-2026:2115-1 Security update for gnutls | 2 месяца назад | |||
openSUSE-SU-2026:20778-1 Security update for gnutls | 2 месяца назад | |||
RLSA-2026:20613 Important: gnutls security update | около 2 месяцев назад | |||
RLSA-2026:20612 Important: gnutls security update | около 2 месяцев назад | |||
ELSA-2026-50346 ELSA-2026-50346: gnutls security fix update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-20613 ELSA-2026-20613: gnutls security update (IMPORTANT) | 15 дней назад | |||
ELSA-2026-20612 ELSA-2026-20612: gnutls security update (IMPORTANT) | около 1 месяца назад |
Уязвимостей на страницу