Details:
The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS.
Security Fix(es):
libtasn1: Inefficient DER Decoding in libtasn1 Leading to Potential Remote DoS (CVE-2024-12133)
gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification (CVE-2025-14831)
gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison (CVE-2026-3833)
gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment (CVE-2026-33845)
gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly (CVE-2026-33846)
gnutls: Fix qsort comparator in DTLS reassembly (CVE-2026-42009)
gnutls: gnutls: Authentication Bypass via NUL Character in Username (CVE-2026-42010)
gnutls: gnutls: Security bypass due to incorrect name constraint handling (CVE-2026-42011)
gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs (CVE-2026-42012)
gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name (CVE-2026-42013)
gnutls: gnutls: Information disclosure via heap overread in RSA key exchange (CVE-2026-5260)
gnutls: Fix use-after-free in gnutls_pkcs11_token_set_pin (CVE-2026-42014)
gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling (CVE-2026-42015)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
0:3.6.16-5.el8_6.50:3.6.16-5.el8_6.50:3.6.16-5.el8_6.50:3.6.16-5.el8_6.50:3.6.16-5.el8_6.50:3.6.16-5.el8_6.50:3.6.16-5.el8_6.50:3.6.16-5.el8_6.50:3.6.16-5.el8_6.50:4.13-3.el8_6.2Exploitability
AV:NAC:LPR:NUI:NScope
S:UImpact
C:LI:NA:H8.2/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H