Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:41921: Important: gnutls security update

This Red Hat security advisory addresses multiple vulnerabilities in the GnuTLS library, including certificate validation bypasses, denial-of-service conditions via DTLS handling flaws, and memory corruption issues. The CVSS scores for the listed CVEs range from Medium to High, with examples like CVE-2026-33845 and CVE-2026-33846 rated at 7.5 (HIGH). Affected systems are specifically Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions on various architectures, and the remediation is to apply the update via the provided Red Hat channel.
Read Full Article →

Red Hat Product Errata RHSA-2026:41921 - Security Advisory Issued: 2026-07-20 Updated: 2026-07-20 RHSA-2026:41921 - Security Advisory Overview Updated Packages Synopsis Important: gnutls security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for gnutls is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS. Security Fix(es): gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison (CVE-2026-3833) gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment (CVE-2026-33845) gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly (CVE-2026-33846) gnutls: Fix qsort comparator in DTLS reassembly (CVE-2026-42009) gnutls: gnutls: Authentication Bypass via NUL Character in Username (CVE-2026-42010) gnutls: gnutls: Security bypass due to incorrect name constraint handling (CVE-2026-42011) gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs (CVE-2026-42012) gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name (CVE-2026-42013) gnutls: gnutls: Information disclosure via heap overread in RSA key exchange (CVE-2026-5260) gnutls: Fix use-after-free in gnutls_pkcs11_token_set_pin (CVE-2026-42014) gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling (CVE-2026-42015) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.2 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2 s390x Fixes BZ - 2445763 - CVE-2026-3833 gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison BZ - 2450624 - CVE-2026-33845 gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment BZ - 2450625 - CVE-2026-33846 gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly BZ - 2467279 - CVE-2026-42009 gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability BZ - 2467289 - CVE-2026-42010 gnutls: gnutls: Authentication Bypass via NUL Character in Username BZ - 2467437 - CVE-2026-42011 gnutls: gnutls: Security bypass due to incorrect name constraint handling BZ - 2467441 - CVE-2026-42012 gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs BZ - 2467448 - CVE-2026-42013 gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name BZ - 2467450 - CVE-2026-5260 gnutls: gnutls: Information disclosure via heap overread in RSA key exchange BZ - 2467451 - CVE-2026-42014 gnutls: gnutls: Use-after-free in gnutls_pkcs11_token_set_pin BZ - 2467678 - CVE-2026-42015 gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling CVEs CVE-2026-3833 CVE-2026-5260 CVE-2026-33845 CVE-2026-33846 CVE-2026-42009 CVE-2026-42010 CVE-2026-42011 CVE-2026-42012 CVE-2026-42013 CVE-2026-42014 CVE-2026-42015 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.2 SRPM gnutls-3.7.6-21.el9_2.7.src.rpm SHA-256: cf1b8ae9ce7fa25b9933f240c93cb72d2f9da68cc808268554e7d8f8b35b327e x86_64 gnutls-3.7.6-21.el9_2.7.i686.rpm SHA-256: eef92a094c4c4376390f3d3cafb26c301001968986f0ce7a2367faaea256fdf1 gnutls-3.7.6-21.el9_2.7.x86_64.rpm SHA-256: 2da6a9b7b7dc107dbda80462619095b5d49cf2efd95b73c03b118df4366356a7 gnutls-c++-3.7.6-21.el9_2.7.i686.rpm SHA-256: c1add61edd505deba8c37b56a75539b40cc613666929dda13441bbb26b5f284a gnutls-c++-3.7.6-21.el9_2.7.x86_64.rpm SHA-256: d641df904e6b1734bb1e0f534f06e3443d8f7f6496c401793a588084781de4b3 gnutls-c++-debuginfo-3.7.6-21.el9_2.7.i686.rpm SHA-256: 04d8da9bec5c7015a00695ecca4b749709394fd619c72bf63a018025ff029370 gnutls-c++-debuginfo-3.7.6-21.el9_2.7.i686.rpm SHA-256: 04d8da9bec5c7015a00695ecca4b749709394fd619c72bf63a018025ff029370 gnutls-c++-debuginfo-3.7.6-21.el9_2.7.x86_64.rpm SHA-256: 9a15f63b80034790c3ba3b77693baa5150c9b1050cd3dbd3fd513342ab7d2de9 gnutls-c++-debuginfo-3.7.6-21.el9_2.7.x86_64.rpm SHA-256: 9a15f63b80034790c3ba3b77693baa5150c9b1050cd3dbd3fd513342ab7d2de9 gnutls-dane-3.7.6-21.el9_2.7.i686.rpm SHA-256: cb97b48f3afc3436de17ce67a569715c8528af9fa868fd441fac7a3327db815c gnutls-dane-3.7.6-21.el9_2.7.x86_64.rpm SHA-256: 5cbec1b1342d9100f5a218402fbaa9102f08e78f0613249cb5e1667d256e1fe0 gnutls-dane-debuginfo-3.7.6-21.el9_2.7.i686.rpm SHA-256: 31a74a7c8534f419eefe2489d4b7f4a25a5014dc5ebf7a154b944c2b8b8dd0f2 gnutls-dane-debuginfo-3.7.6-21.el9_2.7.i686.rpm SHA-256: 31a74a7c8534f419eefe2489d4b7f4a25a5014dc5ebf7a154b944c2b8b8dd0f2 gnutls-dane-debuginfo-3.7.6-21.el9_2.7.x86_64.rpm SHA-256: 0a12317357a7806c2642dc2363e6df5663ff93f2915d08fd1aa53a565af2ee34 gnutls-dane-debuginfo-3.7.6-21.el9_2.7.x86_64.rpm SHA-256: 0a12317357a7806c2642dc2363e6df5663ff93f2915d08fd1aa53a565af2ee34 gnutls-debuginfo-3.7.6-21.el9_2.7.i686.rpm SHA-256: 821ea48adac9f6336878813b3e72db31195782032be6ce1cd0e8cf0aa1a2dbec gnutls-debuginfo-3.7.6-21.el9_2.7.i686.rpm SHA-256: 821ea48adac9f6336878813b3e72db31195782032be6ce1cd0e8cf0aa1a2dbec gnutls-debuginfo-3.7.6-21.el9_2.7.x86_64.rpm SHA-256: 265f4c85a5bc461d585c6db57fcb8b2b59279630f2ea7ba86198e9303f27c71a gnutls-debuginfo-3.7.6-21.el9_2.7.x86_64.rpm SHA-256: 265f4c85a5bc461d585c6db57fcb8b2b59279630f2ea7ba86198e9303f27c71a gnutls-debugsource-3.7.6-21.el9_2.7.i686.rpm SHA-256: b411baffb23a0959ac2c016648625c8a4fb80382e5b187b156559801b8bb2edb gnutls-debugsource-3.7.6-21.el9_2.7.i686.rpm SHA-256: b411baffb23a0959ac2c016648625c8a4fb80382e5b187b156559801b8bb2edb gnutls-debugsource-3.7.6-21.el9_2.7.x86_64.rpm SHA-256: bc09dbb35abbc5a936635bc72ac75a2a571894f02e32cdd5796cb772733d20b1 gnutls-debugsource-3.7.6-21.el9_2.7.x86_64.rpm SHA-256: bc09dbb35abbc5a936635bc72ac75a2a571894f02e32cdd5796cb772733d20b1 gnutls-devel-3.7.6-21.el9_2.7.i686.rpm SHA-256: 7fed78e5794201bbab7a9565e64f5bb3803476fa6e420d97e9a32e8d5dd4025f gnutls-devel-3.7.6-21.el9_2.7.x86_64.rpm SHA-256: 26e041713aa207af118e98bbf466b090d6ee537afdd3a1283cb3346c0ee5d55c gnutls-utils-3.7.6-21.el9_2.7.x86_64.rpm SHA-256: bfc7c7eb8cab84de4464372f1c1e5bd005ad54890272b78e55ea30d190636a98 gnutls-utils-debuginfo-3.7.6-21.el9_2.7.i686.rpm SHA-256: f889f07bf4e2fb26e7bf78856847590aed53838986429f91901432b5ce43d594 gnutls-utils-debuginfo-3.7.6-21.el9_2.7.i686.rpm SHA-256: f889f07bf4e2fb26e7bf78856847590aed53838986429f91901432b5ce43d594 gnutls-utils-debuginfo-3.7.6-21.el9_2.7.x86_64.rpm SHA-256: d0ebd4749f216a941cedaf36196c98960bd0c8ef7e2fcd1f3d2ae7a5c8117097 gnutls-utils-debuginfo-3.7.6-21.el9_2.7.x86_64.rpm SHA-256: d0ebd4749f216a941cedaf36196c98960bd0c8ef7e2fcd1f3d2ae7a5c8117097 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 SRPM gnutls-3.7.6-21.el9_2.7.src.rpm SHA-256: cf1b8ae9ce7fa25b9933f240c93cb72d2f9da68cc808268554e7d8f8b35b327e ppc64le gnutls-3.7.6-21.el9_2.7.ppc64le.rpm SHA-256: 1c6011caed9d4fc09230da543437f060efc6aa1f9559ab603439397a88aaa0c3 gnutls-c++-3.7.6-21.el9_2.7.ppc64le.rpm SHA-256: f0073074009848d00352fa6b14c66c1fd0b36243eb1eec81eb0c698417cc6b27 gnutls-c++-debuginfo-3.7.6-21.el9_2.7.ppc64le.rpm SHA-256: aaaef4a82888e9e40a30bc3c7bf9cfc524a0f187c9e8e279b7397b16f9072cfd gnutls-c++-debuginfo-3.7.6-21.el9_2.7.ppc64le.rpm SHA-256: aaaef4a82888e9e40a30bc3c7bf9cfc524a0f187c9e8e279b7397b16f9072cfd gnutls-dane-3.7.6-21.el9_2.7.ppc64le.rpm SHA-256: 0ef0af4408dfe680e099b50a5e78fcb7b4119a87fa7ab3efe5efc2700fee204e gnutls-dane-debuginfo-3.7.6-21.el9_2.7.ppc64le.rpm SHA-256: 23740d934c18988420d3a8f61e2887fcd8f65443481a6236e5e0ebd0ae9b17ed gnutls-dane-debuginfo-3.7.6-21.el9_2.7.ppc64le.rpm SHA-256: 23740d934c18988420d3a8f61e2887fcd8f65443481a6236e5e0ebd0ae9b17ed gnutls-debuginfo-3.7.6-21.el9_2.7.ppc64le.rpm SHA-256: 27d77f1d13381dc484e7b5a3f23fb3c38d66dbc2ccb0e25bf7b915035201e9e1 gnutls-debuginfo-3.7.6-21.el9_2.7.ppc64le.rpm SHA-256: 27d77f1d13381dc484e7b5a3f23fb3c38d66dbc2ccb0e25bf7b915035201e9e1 gnutls-debugsource-3.7.6-21.el9_2.7.ppc64le.rpm SHA-256: 18b459131f0205c53029ecbd2b9f6420394c3d6095effae4d3a78d5f1c395559 gnutls-debugsource-3.7.6-21.el9_2.7.ppc64le.rpm SHA-256: 18b459131f0205c53029ecbd2b9f6420394c3d6095effae4d3a78d5f1c395559 gnutls-devel-3.7.6-21.el9_2.7.ppc64le.rpm SHA-256: dc89ae927708ee7704450036e0dcf84796bcc2380b5ede7179ee58a66fd8b67a gnutls-utils-3.7.6-21.el9_2.7.ppc64le.rpm SHA-256: f2a07aa7f3fdc8fc5b3cfa3491886a948e935b3ca4908927c605769a977a1751 gnutls-utils-debuginfo-3.7.6-21.el9_2.7.ppc64le.rpm SHA-256: 77ff9ad8eedd8abf8859e57821abecdb2dae4be2ed92ed1e606475ea36589685 gnut

Share this article