- What: Security update for gnutls and libtasn1
- Impact: Red Hat Enterprise Linux 8.4 systems
Red Hat Product Errata RHSA-2026:33125 - Security Advisory Issued: 2026-06-29 Updated: 2026-06-29 RHSA-2026:33125 - Security Advisory Overview Updated Packages Synopsis Important: gnutls and libtasn1 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for multiple packages is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS. Security Fix(es): libtasn1: Inefficient DER Decoding in libtasn1 Leading to Potential Remote DoS (CVE-2024-12133) gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification (CVE-2025-14831) gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison (CVE-2026-3833) gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment (CVE-2026-33845) gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly (CVE-2026-33846) gnutls: Fix qsort comparator in DTLS reassembly (CVE-2026-42009) gnutls: gnutls: Authentication Bypass via NUL Character in Username (CVE-2026-42010) gnutls: gnutls: Security bypass due to incorrect name constraint handling (CVE-2026-42011) gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs (CVE-2026-42012) gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name (CVE-2026-42013) gnutls: gnutls: Information disclosure via heap overread in RSA key exchange (CVE-2026-5260) gnutls: Fix use-after-free in gnutls_pkcs11_token_set_pin (CVE-2026-42014) gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling (CVE-2026-42015) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 x86_64 Red Hat Enterprise Linux Server - AUS 8.4 x86_64 Fixes BZ - 2344611 - CVE-2024-12133 libtasn1: Inefficient DER Decoding in libtasn1 Leading to Potential Remote DoS BZ - 2423177 - CVE-2025-14831 gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification BZ - 2445763 - CVE-2026-3833 gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison BZ - 2450624 - CVE-2026-33845 gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment BZ - 2450625 - CVE-2026-33846 gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly BZ - 2467279 - CVE-2026-42009 gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability BZ - 2467289 - CVE-2026-42010 gnutls: gnutls: Authentication Bypass via NUL Character in Username BZ - 2467437 - CVE-2026-42011 gnutls: gnutls: Security bypass due to incorrect name constraint handling BZ - 2467441 - CVE-2026-42012 gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs BZ - 2467448 - CVE-2026-42013 gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name BZ - 2467450 - CVE-2026-5260 gnutls: gnutls: Information disclosure via heap overread in RSA key exchange BZ - 2467451 - CVE-2026-42014 gnutls: gnutls: Use-after-free in gnutls_pkcs11_token_set_pin BZ - 2467678 - CVE-2026-42015 gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling CVEs CVE-2024-12133 CVE-2025-14831 CVE-2026-3833 CVE-2026-5260 CVE-2026-33845 CVE-2026-33846 CVE-2026-42009 CVE-2026-42010 CVE-2026-42011 CVE-2026-42012 CVE-2026-42013 CVE-2026-42014 CVE-2026-42015 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 SRPM gnutls-3.6.14-10.el8_4.1.src.rpm SHA-256: e370acc62e4fd204a9b633f69554a702429393f62fdec21fbd8b5aa5cdf633a5 libtasn1-4.13-3.el8_4.1.src.rpm SHA-256: 37a3b72ab2a70881e0bbdfa5a46ddef0d04d634568597a823b2e5c8b07ad8649 x86_64 gnutls-3.6.14-10.el8_4.1.i686.rpm SHA-256: b7a2c7974e1961bee0153c74d367eb35f22b0330b51f4ef04371a7c07614fa90 gnutls-3.6.14-10.el8_4.1.x86_64.rpm SHA-256: 5c6e342d1a4142211b3a04d8b4e157401821cb92a37e78acb0667c1ce869563b gnutls-c++-3.6.14-10.el8_4.1.i686.rpm SHA-256: ab08c15b59472b4df82232560b980aa8ec3dbe86c336449067347dced9b5de99 gnutls-c++-3.6.14-10.el8_4.1.x86_64.rpm SHA-256: 2551b04b5f9b5686e8298a574fa3988045aa637d1b1446511da3b041db87c19c gnutls-c++-debuginfo-3.6.14-10.el8_4.1.i686.rpm SHA-256: dfef761f78becff7767a5a376ec48bfd45e6b6aa85a4bb41a0122ddb3d10b135 gnutls-c++-debuginfo-3.6.14-10.el8_4.1.i686.rpm SHA-256: dfef761f78becff7767a5a376ec48bfd45e6b6aa85a4bb41a0122ddb3d10b135 gnutls-c++-debuginfo-3.6.14-10.el8_4.1.x86_64.rpm SHA-256: 11862c15f6877be0fa552489065ff3a6e177b4ba17c527d6470a94a3712b376f gnutls-c++-debuginfo-3.6.14-10.el8_4.1.x86_64.rpm SHA-256: 11862c15f6877be0fa552489065ff3a6e177b4ba17c527d6470a94a3712b376f gnutls-dane-3.6.14-10.el8_4.1.i686.rpm SHA-256: 81794ef97405337c3caa5dff992c68141ede2bb4b7dd0dff6d11a2e947f7b5e6 gnutls-dane-3.6.14-10.el8_4.1.x86_64.rpm SHA-256: 946504ee75fb6ea36fe9f9c195ad2353c2bdf4598bf191526a7d614be3bb73fd gnutls-dane-debuginfo-3.6.14-10.el8_4.1.i686.rpm SHA-256: 90052892cd846136e1bd0372b764ef8511546c9f42d916342187fdfef8e792c0 gnutls-dane-debuginfo-3.6.14-10.el8_4.1.i686.rpm SHA-256: 90052892cd846136e1bd0372b764ef8511546c9f42d916342187fdfef8e792c0 gnutls-dane-debuginfo-3.6.14-10.el8_4.1.x86_64.rpm SHA-256: 45fe51333328b57999b0f5182f79a3d058bb1c8f8e94efb11d4a12bb6181749c gnutls-dane-debuginfo-3.6.14-10.el8_4.1.x86_64.rpm SHA-256: 45fe51333328b57999b0f5182f79a3d058bb1c8f8e94efb11d4a12bb6181749c gnutls-debuginfo-3.6.14-10.el8_4.1.i686.rpm SHA-256: 7e4f63c8811560d209e95077d954e2ef8123fc34faf00cb7e93782ee499a2050 gnutls-debuginfo-3.6.14-10.el8_4.1.i686.rpm SHA-256: 7e4f63c8811560d209e95077d954e2ef8123fc34faf00cb7e93782ee499a2050 gnutls-debuginfo-3.6.14-10.el8_4.1.x86_64.rpm SHA-256: 9072187bfb362cc1a5645385c1ff4fb030df6099270bdb48fb10f23c8754cafd gnutls-debuginfo-3.6.14-10.el8_4.1.x86_64.rpm SHA-256: 9072187bfb362cc1a5645385c1ff4fb030df6099270bdb48fb10f23c8754cafd gnutls-debugsource-3.6.14-10.el8_4.1.i686.rpm SHA-256: 01aeab935a342301a92ca03435557dfc4354d791c478629a870117b5a78e7128 gnutls-debugsource-3.6.14-10.el8_4.1.i686.rpm SHA-256: 01aeab935a342301a92ca03435557dfc4354d791c478629a870117b5a78e7128 gnutls-debugsource-3.6.14-10.el8_4.1.x86_64.rpm SHA-256: d2a6762ecb28580bd6614af799c64e6e31295bd08df8ae25de0eb9b810a2fbf4 gnutls-debugsource-3.6.14-10.el8_4.1.x86_64.rpm SHA-256: d2a6762ecb28580bd6614af799c64e6e31295bd08df8ae25de0eb9b810a2fbf4 gnutls-devel-3.6.14-10.el8_4.1.i686.rpm SHA-256: db143d8034a91aaa0396f1a0ae1e69685669b874e71ef683513dc8ff33f1e9cb gnutls-devel-3.6.14-10.el8_4.1.x86_64.rpm SHA-256: 14dcef93f205f483979d9514b66aca510848e54d3a2ad71a5f423315cc4cf7f0 gnutls-utils-3.6.14-10.el8_4.1.x86_64.rpm SHA-256: 76ca7740e9148f6364534f5a140a6e650d5b47e43f69e0b92dad8c6c2e25f140 gnutls-utils-debuginfo-3.6.14-10.el8_4.1.i686.rpm SHA-256: 06874ba7a99566eb94fafa9ab9fdda265758ab38622c428beaf2481c0d24cdcf gnutls-utils-debuginfo-3.6.14-10.el8_4.1.i686.rpm SHA-256: 06874ba7a99566eb94fafa9ab9fdda265758ab38622c428beaf2481c0d24cdcf gnutls-utils-debuginfo-3.6.14-10.el8_4.1.x86_64.rpm SHA-256: 367869ca7261a8b3105208d78229f77a73831f94ea36fa162e11d9e12956deab gnutls-utils-debuginfo-3.6.14-10.el8_4.1.x86_64.rpm SHA-256: 367869ca7261a8b3105208d78229f77a73831f94ea36fa162e11d9e12956deab libtasn1-4.13-3.el8_4.1.i686.rpm SHA-256: 2a3fa2f7aead817927fc3490acd5e9737edef7397ba002d9145fdc8363a7ffa0 libtasn1-4.13-3.el8_4.1.x86_64.rpm SHA-256: e7ee01f6cff74e62cd59bf448d1c4d44e3b04f4d4af1b8836408201e5451b63c libtasn1-debuginfo-4.13-3.el8_4.1.i686.rpm SHA-256: 59455df3ed0e3a722a2d8c58768f596524f394671f031cba53f01954b46d2c18 libtasn1-debuginfo-4.13-3.el8_4.1.i686.rpm SHA-256: 59455df3ed0e3a722a2d8c58768f596524f394671f031cba53f01954b46d2c18 libtasn1-debuginfo-4.13-3.el8_4.1.x86_64.rpm SHA-256: 7d67d10261a40d89ebb9ce49fe98868df468656f54c4a864ac23060a2f588496 libtasn1-debuginfo-4.13-3.el8_4.1.x86_64.rpm SHA-256: 7d67d10261a40d89ebb9ce49fe98868df468656f54c4a864ac23060a2f588496 libtasn1-debugsource-4.13-3.el8_4.1.i686.rpm SHA-256: 8f7520971b2c5f07db795a81e9d9b09c3db3b1430705e6b8f1bd19da46980a32 libtasn1-debugsource-4.13-3.el8_4.1.i686.rpm SHA-256: 8f7520971b2c5f07db795a81e9d9b09c3db3b1430705e6b8f1bd19da46980a32 libtasn1-debugsource-4.13-3.el8_4.1.x86_64.rpm SHA-256: 6af9401a58149d2d594a679e63466694c5bd991d1d96b6724244662ebdc8cebc libtasn1-debugsource-4.13-3.el8_4.1.x86_64.rpm SHA-256: 6af9401a58149d2d594a679e63466694c5bd991d1d96b6724244662ebdc8cebc libtasn1-devel-4.13-3.el8_4.1.i686.rpm SHA-256: 5e226d3126d40aada703402ad22856d45954c9c3a21d502f11cfd26d0b4fb682 libtasn1-devel-4.13-3.el8_4.1.x86_64.rpm SHA-256: e3964bcea54c149c5237c63d9be8a7f071fb68eb180fd94829857c50607161d1 libtasn1-tools-4.13-3.el8_4.1.x86_64.rpm SHA-256: 4df8414e14790705a44e0a164ab2be2a462cee2af78f6aa0130bc3c84cd6f18a libtasn1-tools-debuginfo-4.13-3.el8_4.1.i686.rpm SHA-256: 1c49f8e438bb1eab4427baddcc9d1bed819e196cd137d08d5d3b7ceba38a1189 libtasn1-tools-debuginfo-4.1