Security News

Cybersecurity news aggregator

🔄
INFO Updates Red Hat Errata

RHSA-2026:32962: Important: gnutls security update

  • What: Security update for gnutls library
  • Impact: Addresses policy bypass vulnerability in TLS implementation
Read Full Article →

Red Hat Product Errata RHSA-2026:32962 - Security Advisory Issued: 2026-06-29 Updated: 2026-06-29 RHSA-2026:32962 - Security Advisory Overview Updated Packages Synopsis Important: gnutls security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for gnutls is now available for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS. Security Fix(es): gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison (CVE-2026-3833) gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment (CVE-2026-33845) gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly (CVE-2026-33846) gnutls: Fix qsort comparator in DTLS reassembly (CVE-2026-42009) gnutls: gnutls: Authentication Bypass via NUL Character in Username (CVE-2026-42010) gnutls: gnutls: Security bypass due to incorrect name constraint handling (CVE-2026-42011) gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs (CVE-2026-42012) gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name (CVE-2026-42013) gnutls: gnutls: Information disclosure via heap overread in RSA key exchange (CVE-2026-5260) gnutls: Fix use-after-free in gnutls_pkcs11_token_set_pin (CVE-2026-42014) gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling (CVE-2026-42015) guntls: gnutls: Information disclosure via timing side-channel in PKCS#7 padding removal (CVE-2026-5419) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.4 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4 s390x Fixes BZ - 2445763 - CVE-2026-3833 gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison BZ - 2450624 - CVE-2026-33845 gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment BZ - 2450625 - CVE-2026-33846 gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly BZ - 2467279 - CVE-2026-42009 gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability BZ - 2467289 - CVE-2026-42010 gnutls: gnutls: Authentication Bypass via NUL Character in Username BZ - 2467437 - CVE-2026-42011 gnutls: gnutls: Security bypass due to incorrect name constraint handling BZ - 2467441 - CVE-2026-42012 gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs BZ - 2467448 - CVE-2026-42013 gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name BZ - 2467450 - CVE-2026-5260 gnutls: gnutls: Information disclosure via heap overread in RSA key exchange BZ - 2467451 - CVE-2026-42014 gnutls: gnutls: Use-after-free in gnutls_pkcs11_token_set_pin BZ - 2467678 - CVE-2026-42015 gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling BZ - 2467686 - CVE-2026-5419 gnutls: gnutls: Information disclosure via timing side-channel in PKCS#7 padding removal CVEs CVE-2026-3833 CVE-2026-5260 CVE-2026-5419 CVE-2026-33845 CVE-2026-33846 CVE-2026-42009 CVE-2026-42010 CVE-2026-42011 CVE-2026-42012 CVE-2026-42013 CVE-2026-42014 CVE-2026-42015 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.4 SRPM gnutls-3.8.3-4.el9_4.6.src.rpm SHA-256: aa1df2143740cab4b785375eb572fecafaab1bebfaab35ce35fb6a3a9f0ca323 x86_64 gnutls-3.8.3-4.el9_4.6.i686.rpm SHA-256: bdb630cad173714f78396f5dc6f4aee850338b98dee93e103e44f8c2656046d0 gnutls-3.8.3-4.el9_4.6.x86_64.rpm SHA-256: d169392ee999426928014347481eae6c7cf1469c1b36198adf5c1517967a60c8 gnutls-c++-3.8.3-4.el9_4.6.i686.rpm SHA-256: a06417f0f6cfd63bcaea20112a8f64ba0ec51b94d05ae52c35c657763391f7e8 gnutls-c++-3.8.3-4.el9_4.6.x86_64.rpm SHA-256: 6e9ca62eb864b65d64d81d42f9ef0a0c3045c092354d1e0cd79989fdf3f14d7b gnutls-c++-debuginfo-3.8.3-4.el9_4.6.i686.rpm SHA-256: 34d87937c10cd46c3043f4ff9c836696fe1da5abe9bb37a6c5156fff399b27c2 gnutls-c++-debuginfo-3.8.3-4.el9_4.6.i686.rpm SHA-256: 34d87937c10cd46c3043f4ff9c836696fe1da5abe9bb37a6c5156fff399b27c2 gnutls-c++-debuginfo-3.8.3-4.el9_4.6.x86_64.rpm SHA-256: 4936c2b1891fd89509f72e460d37e51dd6ec3bf227d8843df73470053f33a50a gnutls-c++-debuginfo-3.8.3-4.el9_4.6.x86_64.rpm SHA-256: 4936c2b1891fd89509f72e460d37e51dd6ec3bf227d8843df73470053f33a50a gnutls-dane-3.8.3-4.el9_4.6.i686.rpm SHA-256: 3f3b2fdf7a28b198efb0b2a7b0ce86823bdb76da919c2253edac4d746636727e gnutls-dane-3.8.3-4.el9_4.6.x86_64.rpm SHA-256: 6104d461a67be9302e4feebccf2c913fe7fe16cf7fc10675443f3f922f2a1620 gnutls-dane-debuginfo-3.8.3-4.el9_4.6.i686.rpm SHA-256: 923c94fc02d5ede644f345a31dff7fc3fb7548a9037492925b21861345599d48 gnutls-dane-debuginfo-3.8.3-4.el9_4.6.i686.rpm SHA-256: 923c94fc02d5ede644f345a31dff7fc3fb7548a9037492925b21861345599d48 gnutls-dane-debuginfo-3.8.3-4.el9_4.6.x86_64.rpm SHA-256: 81c781d3185e5e97e3eae8a4411f50c519afe8df6a8b6cb162a0786d6046252a gnutls-dane-debuginfo-3.8.3-4.el9_4.6.x86_64.rpm SHA-256: 81c781d3185e5e97e3eae8a4411f50c519afe8df6a8b6cb162a0786d6046252a gnutls-debuginfo-3.8.3-4.el9_4.6.i686.rpm SHA-256: b38e46bf15438cdd5bf09d3ad0b72d91dffc05032b09f4a8ec9903749ffd00ad gnutls-debuginfo-3.8.3-4.el9_4.6.i686.rpm SHA-256: b38e46bf15438cdd5bf09d3ad0b72d91dffc05032b09f4a8ec9903749ffd00ad gnutls-debuginfo-3.8.3-4.el9_4.6.x86_64.rpm SHA-256: 913dd14b2cf77c3f475642a6075a402a8b520552bb5e753c3d3e4a83c40aea64 gnutls-debuginfo-3.8.3-4.el9_4.6.x86_64.rpm SHA-256: 913dd14b2cf77c3f475642a6075a402a8b520552bb5e753c3d3e4a83c40aea64 gnutls-debugsource-3.8.3-4.el9_4.6.i686.rpm SHA-256: b2303eecbbaa3fa7c88a045b7ee590a2a4cb28e3887bba441391d74a6a8cb306 gnutls-debugsource-3.8.3-4.el9_4.6.i686.rpm SHA-256: b2303eecbbaa3fa7c88a045b7ee590a2a4cb28e3887bba441391d74a6a8cb306 gnutls-debugsource-3.8.3-4.el9_4.6.x86_64.rpm SHA-256: 8abfc961e0d23e08fdb58b582123915dcb336d814d7ea2cf964f99019c8d94e7 gnutls-debugsource-3.8.3-4.el9_4.6.x86_64.rpm SHA-256: 8abfc961e0d23e08fdb58b582123915dcb336d814d7ea2cf964f99019c8d94e7 gnutls-devel-3.8.3-4.el9_4.6.i686.rpm SHA-256: 8a3ec645e44b86ef6a3b7957ee4a374a4f9d9259a4815a481b2ac71127acea25 gnutls-devel-3.8.3-4.el9_4.6.x86_64.rpm SHA-256: 645d2b6ec23b3967bf79928f09faf0c0ceb6a3f9eab2daa833a687639f03a32b gnutls-utils-3.8.3-4.el9_4.6.x86_64.rpm SHA-256: 6f61e6c1d056e286cbf1f72d09ce6e194aae415e2eb35cfcccdc7931bdb75b03 gnutls-utils-debuginfo-3.8.3-4.el9_4.6.i686.rpm SHA-256: af95016f6d9933a9d2e357a3e713dd4af7ff995d32ea242d92ef8cccbc6235b5 gnutls-utils-debuginfo-3.8.3-4.el9_4.6.i686.rpm SHA-256: af95016f6d9933a9d2e357a3e713dd4af7ff995d32ea242d92ef8cccbc6235b5 gnutls-utils-debuginfo-3.8.3-4.el9_4.6.x86_64.rpm SHA-256: 361bac83f12f409a624f43ddb6b1cd23fc2eeb3af9ae6b3913f29008dea4aa1c gnutls-utils-debuginfo-3.8.3-4.el9_4.6.x86_64.rpm SHA-256: 361bac83f12f409a624f43ddb6b1cd23fc2eeb3af9ae6b3913f29008dea4aa1c Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 SRPM gnutls-3.8.3-4.el9_4.6.src.rpm SHA-256: aa1df2143740cab4b785375eb572fecafaab1bebfaab35ce35fb6a3a9f0ca323 ppc64le gnutls-3.8.3-4.el9_4.6.ppc64le.rpm SHA-256: 50cc4353e1a452cb388d8523558fd4bdc232b5c61b963df59987f7b31665497e gnutls-c++-3.8.3-4.el9_4.6.ppc64le.rpm SHA-256: 7b2eda621ffad26046c636fd931282a650fd5d6dd827998bb8172235d8f9f98f gnutls-c++-debuginfo-3.8.3-4.el9_4.6.ppc64le.rpm SHA-256: b5f98cfd463343554e7024a690537171d9463d2801fa58fc94a22593071b276f gnutls-c++-debuginfo-3.8.3-4.el9_4.6.ppc64le.rpm SHA-256: b5f98cfd463343554e7024a690537171d9463d2801fa58fc94a22593071b276f gnutls-dane-3.8.3-4.el9_4.6.ppc64le.rpm SHA-256: 8fe4ee33bff1c3a89da1f4c18617ddf7b1b5c4673ed06138057fc22ed42371d0 gnutls-dane-debuginfo-3.8.3-4.el9_4.6.ppc64le.rpm SHA-256: bfc82c8f1e623a3467e6ad8faafda58701cd5b66f50578955020e0f327274898 gnutls-dane-debuginfo-3.8.3-4.el9_4.6.ppc64le.rpm SHA-256: bfc82c8f1e623a3467e6ad8faafda58701cd5b66f50578955020e0f327274898 gnutls-debuginfo-3.8.3-4.el9_4.6.ppc64le.rpm SHA-256: 703be9f7e00b6137c3073853a5a38e51ec73c144d86131af3f5e88057d811cf3 gnutls-debuginfo-3.8.3-4.el9_4.6.ppc64le.rpm SHA-256: 703be9f7e00b6137c3073853a5a38e51ec73c144d86131af3f5e88057d811cf3 gnutls-debugsource-3.8.3-4.el9_4.6.ppc64le.rpm SHA-256: 062a01d598c5b67d513a34c7c8c6db27e9c7dc9453e153591e5337d2ef8ded05 gnutls-debugsource-3.8.3-4.el9_4.6.ppc64le.rpm SHA-256: 062a01d598c5b67d513a34c7c8c6db27e9c7dc9453e153591e5337d2ef8ded05 gnutls-devel-3.8.3-4.el9_4.6.ppc64le.rpm SHA-256: ceaf748c1d6e8fc4f5d40762d3d839bcafe69ffa5c0961c9080a3068de7c4a73 gnutls-utils-3.8.3-4.el9_4.6.ppc64le.rpm SHA-256: 49

Share this article