Security News

Cybersecurity news aggregator

🔄
INFO Updates Red Hat Errata

RHSA-2026:26409: Important: gnutls security update

  • What: Security update for gnutls
  • Impact: Red Hat Enterprise Linux 10.0 Extended Update Support users need to apply the update
Read Full Article →

Red Hat Product Errata RHSA-2026:26409 - Security Advisory Issued: 2026-06-16 Updated: 2026-06-16 RHSA-2026:26409 - Security Advisory Overview Updated Packages Synopsis Important: gnutls security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for gnutls is now available for Red Hat Enterprise Linux 10.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS. Security Fix(es): gnutls: gnutls: Security bypass allows acceptance of revoked server certificates via crafted OCSP response (CVE-2026-3832) gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison (CVE-2026-3833) gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment (CVE-2026-33845) gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly (CVE-2026-33846) gnutls: Fix qsort comparator in DTLS reassembly (CVE-2026-42009) gnutls: gnutls: Authentication Bypass via NUL Character in Username (CVE-2026-42010) gnutls: gnutls: Security bypass due to incorrect name constraint handling (CVE-2026-42011) gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs (CVE-2026-42012) gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name (CVE-2026-42013) gnutls: gnutls: Information disclosure via heap overread in RSA key exchange (CVE-2026-5260) gnutls: Fix use-after-free in gnutls_pkcs11_token_set_pin (CVE-2026-42014) gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling (CVE-2026-42015) guntls: gnutls: Information disclosure via timing side-channel in PKCS#7 padding removal (CVE-2026-5419) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64 Fixes BZ - 2445762 - CVE-2026-3832 gnutls: gnutls: Security bypass allows acceptance of revoked server certificates via crafted OCSP response BZ - 2445763 - CVE-2026-3833 gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison BZ - 2450624 - CVE-2026-33845 gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment BZ - 2450625 - CVE-2026-33846 gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly BZ - 2467279 - CVE-2026-42009 gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability BZ - 2467289 - CVE-2026-42010 gnutls: gnutls: Authentication Bypass via NUL Character in Username BZ - 2467437 - CVE-2026-42011 gnutls: gnutls: Security bypass due to incorrect name constraint handling BZ - 2467441 - CVE-2026-42012 gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs BZ - 2467448 - CVE-2026-42013 gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name BZ - 2467450 - CVE-2026-5260 gnutls: gnutls: Information disclosure via heap overread in RSA key exchange BZ - 2467451 - CVE-2026-42014 gnutls: Fix use-after-free in gnutls_pkcs11_token_set_pin BZ - 2467678 - CVE-2026-42015 gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling BZ - 2467686 - CVE-2026-5419 guntls: gnutls: Information disclosure via timing side-channel in PKCS#7 padding removal CVEs CVE-2026-3832 CVE-2026-3833 CVE-2026-5260 CVE-2026-5419 CVE-2026-33845 CVE-2026-33846 CVE-2026-42009 CVE-2026-42010 CVE-2026-42011 CVE-2026-42012 CVE-2026-42013 CVE-2026-42014 CVE-2026-42015 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 SRPM gnutls-3.8.9-9.el10_0.19.src.rpm SHA-256: 72ed3763277e3f15f91777edd64439c15890e3ef37cd2940bde2e7a43308e15c x86_64 gnutls-3.8.9-9.el10_0.19.x86_64.rpm SHA-256: 7104cbcdcd746f1264fafa44ed9f26cdf2b5bcb4e10001fe6b216042d71fa13b gnutls-c++-3.8.9-9.el10_0.19.x86_64.rpm SHA-256: 796d4e3b0dafe32d797e06329ca9c947a9b9f96ce81a4dc1ee61e49b533d2b08 gnutls-c++-debuginfo-3.8.9-9.el10_0.19.x86_64.rpm SHA-256: ef592c778409c7e1893a5327f6e2bee8136a1937806e4811a825136efa1dd9a7 gnutls-c++-debuginfo-3.8.9-9.el10_0.19.x86_64.rpm SHA-256: ef592c778409c7e1893a5327f6e2bee8136a1937806e4811a825136efa1dd9a7 gnutls-dane-3.8.9-9.el10_0.19.x86_64.rpm SHA-256: b83ac14ce427738afd8a93bd873b3e04dc32dcb5d8dda4e76f848970e25a3593 gnutls-dane-debuginfo-3.8.9-9.el10_0.19.x86_64.rpm SHA-256: 7e30d784ae5f79a16143bcc3dd39e15e77d4b71d6cd5f1bdb622c87336339e7f gnutls-dane-debuginfo-3.8.9-9.el10_0.19.x86_64.rpm SHA-256: 7e30d784ae5f79a16143bcc3dd39e15e77d4b71d6cd5f1bdb622c87336339e7f gnutls-debuginfo-3.8.9-9.el10_0.19.x86_64.rpm SHA-256: 2a4bd6bcfecc745c88a1bcdc544525b0af8aac8f660a8f6a52c2330b11d9f8fb gnutls-debuginfo-3.8.9-9.el10_0.19.x86_64.rpm SHA-256: 2a4bd6bcfecc745c88a1bcdc544525b0af8aac8f660a8f6a52c2330b11d9f8fb gnutls-debugsource-3.8.9-9.el10_0.19.x86_64.rpm SHA-256: a5087ae7f3a2968518d30e9581b89454f5ee86c04edc3450a7f59ccb72399d83 gnutls-debugsource-3.8.9-9.el10_0.19.x86_64.rpm SHA-256: a5087ae7f3a2968518d30e9581b89454f5ee86c04edc3450a7f59ccb72399d83 gnutls-devel-3.8.9-9.el10_0.19.x86_64.rpm SHA-256: 9f823479c66f2a0ef4ad3ba4bbdac54f2bcf1016edbeed0bea3b8a52e9ec3579 gnutls-fips-3.8.9-9.el10_0.19.x86_64.rpm SHA-256: 3d797cb860ee14000b5806a2fc65ad981c6775257fbd0523a977625b894c80e4 gnutls-utils-3.8.9-9.el10_0.19.x86_64.rpm SHA-256: 25df83cfc7401c342a376a5e0536524dd5074386a3ea23e62ed4729507ec85cf gnutls-utils-debuginfo-3.8.9-9.el10_0.19.x86_64.rpm SHA-256: 60b774e0f6fe070d2ab5a93427ff7800bdcc9e324fd99d31b9ef7393f9b73071 gnutls-utils-debuginfo-3.8.9-9.el10_0.19.x86_64.rpm SHA-256: 60b774e0f6fe070d2ab5a93427ff7800bdcc9e324fd99d31b9ef7393f9b73071 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 SRPM gnutls-3.8.9-9.el10_0.19.src.rpm SHA-256: 72ed3763277e3f15f91777edd64439c15890e3ef37cd2940bde2e7a43308e15c s390x gnutls-3.8.9-9.el10_0.19.s390x.rpm SHA-256: 41d41a936e302f23ce94cd71f963c99109ab55d5f0f112fbad752a5c2ab5fee3 gnutls-c++-3.8.9-9.el10_0.19.s390x.rpm SHA-256: 29f8b58b861c0ce6dd3d24044b6e88cdde4ce1e48f2cb6a662c85b1e62583787 gnutls-c++-debuginfo-3.8.9-9.el10_0.19.s390x.rpm SHA-256: da6799735389ff4fde4c0285398c48e013057abcebb80bbf7f41bd0d5d25f635 gnutls-c++-debuginfo-3.8.9-9.el10_0.19.s390x.rpm SHA-256: da6799735389ff4fde4c0285398c48e013057abcebb80bbf7f41bd0d5d25f635 gnutls-dane-3.8.9-9.el10_0.19.s390x.rpm SHA-256: d6f0456092a25bc7e49c2cfa0417f1a232106df5b4985001fb5738f1b08efda1 gnutls-dane-debuginfo-3.8.9-9.el10_0.19.s390x.rpm SHA-256: c4997ca44dabb87af6f522a3380f93882e612e8034acbcbe5f99c2141a5673e6 gnutls-dane-debuginfo-3.8.9-9.el10_0.19.s390x.rpm SHA-256: c4997ca44dabb87af6f522a3380f93882e612e8034acbcbe5f99c2141a5673e6 gnutls-debuginfo-3.8.9-9.el10_0.19.s390x.rpm SHA-256: a2ab821b46dc2fd9eca1e110e9b94e16c55cd2ad999e0eaf491510050c02e1c0 gnutls-debuginfo-3.8.9-9.el10_0.19.s390x.rpm SHA-256: a2ab821b46dc2fd9eca1e110e9b94e16c55cd2ad999e0eaf491510050c02e1c0 gnutls-debugsource-3.8.9-9.el10_0.19.s390x.rpm SHA-256: e8b707bf59ab55343f53e8c40c8a4f6506ce827f6afe6aa5001b6ad7b84a7da5 gnutls-debugsource-3.8.9-9.el10_0.19.s390x.rpm SHA-256: e8b707bf59ab55343f53e8c40c8a4f6506ce827f6afe6aa5001b6ad7b84a7da5 gnutls-devel-3.8.9-9.el10_0.19.s390x.rpm SHA-256: ea51ce52d4db833780e383fce206fee893c6c4208a0e291019058c1628de8a4c gnutls-fips-3.8.9-9.el10_0.19.s390x.rpm SHA-256: 10f7e6be06d460bfade75f594408b1e6f11290884896fc6d9c28a5d6b54e8d66 gnutls-utils-3.8.9-9.el10_0.19.s390x.rpm SHA-256: de2c4005d05fda253440ea338386eb821cbc3ad5f75d8f05f988fd3bbba400fa gnutls-utils-debuginfo-3.8.9-9.el10_0.19.s390x.rpm SHA-256: 8b9a8ecece6c742ca47beb5f311296ee6a9bf9bd85a72af31c9fd30a21123b2c gnutls-utils-debuginfo-3.8.9-9.el10_0.19.s390x.rpm SHA-256: 8b9a8ecece6c742ca47beb5f311296ee6a9bf9bd85a72af31c9fd30a21123b2c Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 SRPM gnutls-3.8.9-9.el10_0.19.src.rpm SHA-256: 72ed3763277e3f15f91777edd64439c15890e3ef37cd2940bde2e7a43308e15c ppc64le gnutls-3.8.9-9.el10_0.19.ppc64le.rpm SHA-256: dbce6e2c79b4b14b9903a84919ebc206b9f3f99933ea1828cdba9b8102ccbef7 gnutls-c++-3.8.9-9.el10_0.19.ppc64le.rpm SHA-256: e2dde483cb6a0c26555499b6964951d8eadb822d9efaf23e735a32ac045f792b gnutls-c++-debuginfo-3.8.9-9.el10_0.19.ppc64le.rpm SHA-256: 79de5f6a40b07feead31f3c4e6406327e8b78b7b47a8a0a848105f3c9f67749c gnutls-c++-debuginfo-3.8.9-9.el10_0.19.ppc64le.rpm SHA-256: 79de5f6a40b07feead31f3c4e6406327e8b78b7b47a8a0a848105f3c9f67749c gnutls-dane-3.8.9-9.el10_0.19.ppc64le.rpm SHA-256: a8f8e051883a99bf86d6517196d9a1734b91601492eb1d4a1b5c900bd069763e gnutls-dane-debuginfo-3.8.9-9.el10_0.19.pp

Share this article