Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:30004: Important: gnutls security update

This Red Hat security advisory addresses multiple Important-severity vulnerabilities in the GnuTLS library, including certificate validation bypasses, denial of service via DTLS heap buffer overflow and zero-length fragments, authentication bypass via NUL character in usernames, and information disclosure via side channels. The update applies to Red Hat Enterprise Linux 9.6 Extended Update Support, and affected systems should apply the available patch via the standard Red Hat update mechanism; specific CVSS scores and detailed remediation steps are available via the CVE links provided in the original advisory.
Read Full Article →

Red Hat Product Errata RHSA-2026:30004 - Security Advisory Issued: 2026-06-25 Updated: 2026-06-25 RHSA-2026:30004 - Security Advisory Overview Updated Packages Synopsis Important: gnutls security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for gnutls is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS. Security Fix(es): gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison (CVE-2026-3833) gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment (CVE-2026-33845) gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly (CVE-2026-33846) gnutls: Fix qsort comparator in DTLS reassembly (CVE-2026-42009) gnutls: gnutls: Authentication Bypass via NUL Character in Username (CVE-2026-42010) gnutls: gnutls: Security bypass due to incorrect name constraint handling (CVE-2026-42011) gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs (CVE-2026-42012) gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name (CVE-2026-42013) gnutls: gnutls: Information disclosure via heap overread in RSA key exchange (CVE-2026-5260) gnutls: Fix use-after-free in gnutls_pkcs11_token_set_pin (CVE-2026-42014) gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling (CVE-2026-42015) guntls: gnutls: Information disclosure via timing side-channel in PKCS#7 padding removal (CVE-2026-5419) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64 Red Hat Enterprise Linux Server - AUS 9.6 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6 s390x Fixes BZ - 2445763 - CVE-2026-3833 gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison BZ - 2450624 - CVE-2026-33845 gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment BZ - 2450625 - CVE-2026-33846 gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly BZ - 2467279 - CVE-2026-42009 gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability BZ - 2467289 - CVE-2026-42010 gnutls: gnutls: Authentication Bypass via NUL Character in Username BZ - 2467437 - CVE-2026-42011 gnutls: gnutls: Security bypass due to incorrect name constraint handling BZ - 2467441 - CVE-2026-42012 gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs BZ - 2467448 - CVE-2026-42013 gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name BZ - 2467450 - CVE-2026-5260 gnutls: gnutls: Information disclosure via heap overread in RSA key exchange BZ - 2467451 - CVE-2026-42014 gnutls: gnutls: Use-after-free in gnutls_pkcs11_token_set_pin BZ - 2467678 - CVE-2026-42015 gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling BZ - 2467686 - CVE-2026-5419 gnutls: gnutls: Information disclosure via timing side-channel in PKCS#7 padding removal CVEs CVE-2026-3833 CVE-2026-5260 CVE-2026-5419 CVE-2026-33845 CVE-2026-33846 CVE-2026-42009 CVE-2026-42010 CVE-2026-42011 CVE-2026-42012 CVE-2026-42013 CVE-2026-42014 CVE-2026-42015 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 SRPM gnutls-3.8.3-6.el9_6.4.src.rpm SHA-256: 9aa4e181dc8559e2d87279e9a514c788435b59f5a8bf9eec128462f2303eb9f4 x86_64 gnutls-3.8.3-6.el9_6.4.i686.rpm SHA-256: 3f385cc5dd10a6bfae28bc443081a941e075a4e1c4a950469d4b67a2509c8c65 gnutls-3.8.3-6.el9_6.4.x86_64.rpm SHA-256: 4e2c0319c285bf9be7db3f2ec0e1437c07f99ce2f7b32f3de4de946670119dfc gnutls-c++-3.8.3-6.el9_6.4.i686.rpm SHA-256: f68e9ad4b2590d36d09b979bb73fff0a8c4e0a400a669046b11bf6a58af64e59 gnutls-c++-3.8.3-6.el9_6.4.x86_64.rpm SHA-256: 9ad595cd4a9a19139d37a5dc98efe4ee07443d3f7f2109295e9ffc1a91d65e7d gnutls-c++-debuginfo-3.8.3-6.el9_6.4.i686.rpm SHA-256: 6521aca38340433fb486856cf990cea1c7f742aa3abc71097aed0d01181b0c65 gnutls-c++-debuginfo-3.8.3-6.el9_6.4.i686.rpm SHA-256: 6521aca38340433fb486856cf990cea1c7f742aa3abc71097aed0d01181b0c65 gnutls-c++-debuginfo-3.8.3-6.el9_6.4.x86_64.rpm SHA-256: badee0d6c3240eeb993d7d64acfec02aff3a9c6ad3da3f5bb20428111121726a gnutls-c++-debuginfo-3.8.3-6.el9_6.4.x86_64.rpm SHA-256: badee0d6c3240eeb993d7d64acfec02aff3a9c6ad3da3f5bb20428111121726a gnutls-dane-3.8.3-6.el9_6.4.i686.rpm SHA-256: ccbad0599bed9a375d00dd0b0a408ab8751d2d2659d18e34403e9ae1b124ae35 gnutls-dane-3.8.3-6.el9_6.4.x86_64.rpm SHA-256: 17b968ead401558582fcb15ab5a52e2c81f99d7a5dd1823c7288ce1b4a42d5d7 gnutls-dane-debuginfo-3.8.3-6.el9_6.4.i686.rpm SHA-256: b277caab55eaf7b20295ad3d6212357f9eb2d43318c548a47913394bb9ba9f97 gnutls-dane-debuginfo-3.8.3-6.el9_6.4.i686.rpm SHA-256: b277caab55eaf7b20295ad3d6212357f9eb2d43318c548a47913394bb9ba9f97 gnutls-dane-debuginfo-3.8.3-6.el9_6.4.x86_64.rpm SHA-256: bc897ba03c1d1c4a538aba83fbddbe593572f9c6f074f9077b8314762a9c2cac gnutls-dane-debuginfo-3.8.3-6.el9_6.4.x86_64.rpm SHA-256: bc897ba03c1d1c4a538aba83fbddbe593572f9c6f074f9077b8314762a9c2cac gnutls-debuginfo-3.8.3-6.el9_6.4.i686.rpm SHA-256: 4cb961de8daf8618fa4cb35f0167f7947c2da9ddbd0205edd482c5a8d2009539 gnutls-debuginfo-3.8.3-6.el9_6.4.i686.rpm SHA-256: 4cb961de8daf8618fa4cb35f0167f7947c2da9ddbd0205edd482c5a8d2009539 gnutls-debuginfo-3.8.3-6.el9_6.4.x86_64.rpm SHA-256: 50c3a63b10ddc6b9887ccfe8169544a4658e5c17b2c51e3253897cdab9b26048 gnutls-debuginfo-3.8.3-6.el9_6.4.x86_64.rpm SHA-256: 50c3a63b10ddc6b9887ccfe8169544a4658e5c17b2c51e3253897cdab9b26048 gnutls-debugsource-3.8.3-6.el9_6.4.i686.rpm SHA-256: 585c046a6c46416abfcff49d25f4d69cdd80f8c49b835f0535ea8c36a1dc6f79 gnutls-debugsource-3.8.3-6.el9_6.4.i686.rpm SHA-256: 585c046a6c46416abfcff49d25f4d69cdd80f8c49b835f0535ea8c36a1dc6f79 gnutls-debugsource-3.8.3-6.el9_6.4.x86_64.rpm SHA-256: 90f40276353e18b4861bf2ca415efcc8a724604116e7c88e3897b4ee4b1b02de gnutls-debugsource-3.8.3-6.el9_6.4.x86_64.rpm SHA-256: 90f40276353e18b4861bf2ca415efcc8a724604116e7c88e3897b4ee4b1b02de gnutls-devel-3.8.3-6.el9_6.4.i686.rpm SHA-256: 746b4cd848e85340b36bf5b1e5cc6fbd3d7391e9f49bfafcb0316ceecb06a081 gnutls-devel-3.8.3-6.el9_6.4.x86_64.rpm SHA-256: 8bd6bfe63011187620afc937edb56f2d6c990a45d59c3e48ee0004b947db8b72 gnutls-utils-3.8.3-6.el9_6.4.x86_64.rpm SHA-256: c4a4e96e02a522db4e9431cea0bd9e52ff8ecfb21e53bfbb9b42b211ea4aeaaf gnutls-utils-debuginfo-3.8.3-6.el9_6.4.i686.rpm SHA-256: c2faf8f7efca444899d007c36994a565037603f9274140b662cffe37388dece4 gnutls-utils-debuginfo-3.8.3-6.el9_6.4.i686.rpm SHA-256: c2faf8f7efca444899d007c36994a565037603f9274140b662cffe37388dece4 gnutls-utils-debuginfo-3.8.3-6.el9_6.4.x86_64.rpm SHA-256: cc95fed94efe230548037936320133b05a1b4c92af033efdec23941f1bc0f769 gnutls-utils-debuginfo-3.8.3-6.el9_6.4.x86_64.rpm SHA-256: cc95fed94efe230548037936320133b05a1b4c92af033efdec23941f1bc0f769 Red Hat Enterprise Linux Server - AUS 9.6 SRPM gnutls-3.8.3-6.el9_6.4.src.rpm SHA-256: 9aa4e181dc8559e2d87279e9a514c788435b59f5a8bf9eec128462f2303eb9f4 x86_64 gnutls-3.8.3-6.el9_6.4.i686.rpm SHA-256: 3f385cc5dd10a6bfae28bc443081a941e075a4e1c4a950469d4b67a2509c8c65 gnutls-3.8.3-6.el9_6.4.x86_64.rpm SHA-256: 4e2c0319c285bf9be7db3f2ec0e1437c07f99ce2f7b32f3de4de946670119dfc gnutls-c++-3.8.3-6.el9_6.4.i686.rpm SHA-256: f68e9ad4b2590d36d09b979bb73fff0a8c4e0a400a669046b11bf6a58af64e59 gnutls-c++-3.8.3-6.el9_6.4.x86_64.rpm SHA-256: 9ad595cd4a9a19139d37a5dc98efe4ee07443d3f7f2109295e9ffc1a91d65e7d gnutls-c++-debuginfo-3.8.3-6.el9_6.4.i686.rpm SHA-256: 6521aca38340433fb486856cf990cea1c7f742aa3abc71097aed0d01181b0c65 gnutls-c++-debuginfo-3.8.3-6.el9_6.4.i686.rpm SHA-256: 6521aca38340433fb486856cf990cea1c7f742aa3abc71097aed0d01181b0c65 gnutls-c++-debuginfo-3.8.3-6.el9_6.4.x86_64.rpm SHA-256: badee0d6c3240eeb993d7d64acfec02aff3a9c6ad3da3f5bb20428111121726a gnutls-c++-debuginfo-3.8.3-6.el9_6.4.x86_64.rpm SHA-256: badee0d6c3240eeb993d7d64acfec02aff3a9c6ad3da3f5bb20428111121726a gnutls-dane-3.8.3-6.el9_6.4.i686.rpm SHA-256: ccbad0599bed9a375d00dd0b0a408ab8751d2d2659d18e34403e9ae1b124ae35 gnutls-dane-3.8.3-6.el9_6.4.x86_64.rpm SHA-256: 17b968ead401558582fcb15ab5a52e2c81f99d7a5dd1823c7288ce1b4a42d5d7 gnutls-dane-debuginfo-3.8.3-6.el9_6.4.i686.rpm SH

Share this article