Security News

Cybersecurity news aggregator

🔄
INFO Updates Red Hat Errata

RHSA-2026:30849: Important: gnutls and libtasn1 security update

  • What: Security update for gnutls and libtasn1
  • Impact: Red Hat Enterprise Linux 8.6 systems
Read Full Article →

Red Hat Product Errata RHSA-2026:30849 - Security Advisory Issued: 2026-06-29 Updated: 2026-06-29 RHSA-2026:30849 - Security Advisory Overview Updated Packages Synopsis Important: gnutls and libtasn1 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for multiple packages is now available for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS. Security Fix(es): libtasn1: Inefficient DER Decoding in libtasn1 Leading to Potential Remote DoS (CVE-2024-12133) gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification (CVE-2025-14831) gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison (CVE-2026-3833) gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment (CVE-2026-33845) gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly (CVE-2026-33846) gnutls: Fix qsort comparator in DTLS reassembly (CVE-2026-42009) gnutls: gnutls: Authentication Bypass via NUL Character in Username (CVE-2026-42010) gnutls: gnutls: Security bypass due to incorrect name constraint handling (CVE-2026-42011) gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs (CVE-2026-42012) gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name (CVE-2026-42013) gnutls: gnutls: Information disclosure via heap overread in RSA key exchange (CVE-2026-5260) gnutls: Fix use-after-free in gnutls_pkcs11_token_set_pin (CVE-2026-42014) gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling (CVE-2026-42015) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6 x86_64 Red Hat Enterprise Linux Server - AUS 8.6 x86_64 Fixes BZ - 2344611 - CVE-2024-12133 libtasn1: Inefficient DER Decoding in libtasn1 Leading to Potential Remote DoS BZ - 2423177 - CVE-2025-14831 gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification BZ - 2445763 - CVE-2026-3833 gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison BZ - 2450624 - CVE-2026-33845 gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment BZ - 2450625 - CVE-2026-33846 gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly BZ - 2467279 - CVE-2026-42009 gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability BZ - 2467289 - CVE-2026-42010 gnutls: gnutls: Authentication Bypass via NUL Character in Username BZ - 2467437 - CVE-2026-42011 gnutls: gnutls: Security bypass due to incorrect name constraint handling BZ - 2467441 - CVE-2026-42012 gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs BZ - 2467448 - CVE-2026-42013 gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name BZ - 2467450 - CVE-2026-5260 gnutls: gnutls: Information disclosure via heap overread in RSA key exchange BZ - 2467451 - CVE-2026-42014 gnutls: gnutls: Use-after-free in gnutls_pkcs11_token_set_pin BZ - 2467678 - CVE-2026-42015 gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling CVEs CVE-2024-12133 CVE-2025-14831 CVE-2026-3833 CVE-2026-5260 CVE-2026-33845 CVE-2026-33846 CVE-2026-42009 CVE-2026-42010 CVE-2026-42011 CVE-2026-42012 CVE-2026-42013 CVE-2026-42014 CVE-2026-42015 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6 SRPM gnutls-3.6.16-5.el8_6.5.src.rpm SHA-256: 375c13c792b25c17c20d4fc6b3ec1917d8694f55e2560b1c7866b652600924f2 libtasn1-4.13-3.el8_6.2.src.rpm SHA-256: 33b880a67291bdb2967428f64a6da0bf4a56240f6e0388f6f33afc33e7c8ef0b x86_64 gnutls-3.6.16-5.el8_6.5.i686.rpm SHA-256: 893d40e16ad22d2c2bb759c71636dd43f902306fd501423623cf5fad6e369b95 gnutls-3.6.16-5.el8_6.5.x86_64.rpm SHA-256: bafbee39af5513cfea4fa5b97f14ab47ea9714355e8acdfefec3004274f8aceb gnutls-c++-3.6.16-5.el8_6.5.i686.rpm SHA-256: b2c1a5d9e7be96d57e472db2f8f6771a9f26120dc6a3e7a99c215e4a2ab40dde gnutls-c++-3.6.16-5.el8_6.5.x86_64.rpm SHA-256: 15446dd8f1cdbbeec46566056f07c0d4fc3ea75d5c1605fad069a7baab9ed6ff gnutls-c++-debuginfo-3.6.16-5.el8_6.5.i686.rpm SHA-256: 8474737b6509efec8b4526b191a2b6025bf1ea183979cd5963b3802104de94a6 gnutls-c++-debuginfo-3.6.16-5.el8_6.5.i686.rpm SHA-256: 8474737b6509efec8b4526b191a2b6025bf1ea183979cd5963b3802104de94a6 gnutls-c++-debuginfo-3.6.16-5.el8_6.5.x86_64.rpm SHA-256: 71131cb16ef09869d83400a407ee4fc8d9832e0acf41e019a9100425e2771d46 gnutls-c++-debuginfo-3.6.16-5.el8_6.5.x86_64.rpm SHA-256: 71131cb16ef09869d83400a407ee4fc8d9832e0acf41e019a9100425e2771d46 gnutls-dane-3.6.16-5.el8_6.5.i686.rpm SHA-256: ad0273240edb54b9ea88038b0586fc7930349c2ca964854b1ef52b33c399d389 gnutls-dane-3.6.16-5.el8_6.5.x86_64.rpm SHA-256: 17ae33e50297b70c4d0b5ed07d5f2b0728255a8ce423a273d1810b6d1bd7d990 gnutls-dane-debuginfo-3.6.16-5.el8_6.5.i686.rpm SHA-256: 3f68b01c2885c40849f8e77d38c09d17fb6ac0857be037f0106ae598867b4bd7 gnutls-dane-debuginfo-3.6.16-5.el8_6.5.i686.rpm SHA-256: 3f68b01c2885c40849f8e77d38c09d17fb6ac0857be037f0106ae598867b4bd7 gnutls-dane-debuginfo-3.6.16-5.el8_6.5.x86_64.rpm SHA-256: ae3cbcef786a365a1ca2fc691e76fcb7e4bd9bc906ddd52240604f59bc41d74c gnutls-dane-debuginfo-3.6.16-5.el8_6.5.x86_64.rpm SHA-256: ae3cbcef786a365a1ca2fc691e76fcb7e4bd9bc906ddd52240604f59bc41d74c gnutls-debuginfo-3.6.16-5.el8_6.5.i686.rpm SHA-256: 428889e49763f4024d4764fc67b9dc289b8806d09420a897281ba2b0e4556fc9 gnutls-debuginfo-3.6.16-5.el8_6.5.i686.rpm SHA-256: 428889e49763f4024d4764fc67b9dc289b8806d09420a897281ba2b0e4556fc9 gnutls-debuginfo-3.6.16-5.el8_6.5.x86_64.rpm SHA-256: 96dd2d0c2a2f7d0d0ba97541a3c3f4ba09106e7df35fc11015aeec1b7be128fb gnutls-debuginfo-3.6.16-5.el8_6.5.x86_64.rpm SHA-256: 96dd2d0c2a2f7d0d0ba97541a3c3f4ba09106e7df35fc11015aeec1b7be128fb gnutls-debugsource-3.6.16-5.el8_6.5.i686.rpm SHA-256: 3f799698687c92629ca4455dcf792e341406febd2b4728ffa8bf9bb4c4b5c9fd gnutls-debugsource-3.6.16-5.el8_6.5.i686.rpm SHA-256: 3f799698687c92629ca4455dcf792e341406febd2b4728ffa8bf9bb4c4b5c9fd gnutls-debugsource-3.6.16-5.el8_6.5.x86_64.rpm SHA-256: e4bee64b52a4c1f92f9c27eb5ec90d78b672a67950ce0995c7755c0cc16dddbd gnutls-debugsource-3.6.16-5.el8_6.5.x86_64.rpm SHA-256: e4bee64b52a4c1f92f9c27eb5ec90d78b672a67950ce0995c7755c0cc16dddbd gnutls-devel-3.6.16-5.el8_6.5.i686.rpm SHA-256: 664857a6d61c06a383d8f9f7fd9f659469e48c5e1b4d433ad439c7ae0569f1da gnutls-devel-3.6.16-5.el8_6.5.x86_64.rpm SHA-256: f2fa55ba7e8677489ebb0b342f1da804b4b139ce73efb3e609487b6848eb80a0 gnutls-utils-3.6.16-5.el8_6.5.x86_64.rpm SHA-256: 6a97b1942df09327b420567d00ac58819252245019cf5ecc9b48bb334cf2262e gnutls-utils-debuginfo-3.6.16-5.el8_6.5.i686.rpm SHA-256: a6e09bb30761d923dbdd79a05c06887e5a43ccb368239640bf3751bacb37f11d gnutls-utils-debuginfo-3.6.16-5.el8_6.5.i686.rpm SHA-256: a6e09bb30761d923dbdd79a05c06887e5a43ccb368239640bf3751bacb37f11d gnutls-utils-debuginfo-3.6.16-5.el8_6.5.x86_64.rpm SHA-256: d12b6b9ada3c0c73acb0e091bfbc7c196068d0f5fa3e80147c6360b9b418a335 gnutls-utils-debuginfo-3.6.16-5.el8_6.5.x86_64.rpm SHA-256: d12b6b9ada3c0c73acb0e091bfbc7c196068d0f5fa3e80147c6360b9b418a335 libtasn1-4.13-3.el8_6.2.i686.rpm SHA-256: cf33436a1279e831c460505b395e3a381645d624c301e68e1e8136d208635b76 libtasn1-4.13-3.el8_6.2.x86_64.rpm SHA-256: 93000adcf797b47bff6d8941dfb2aa9f71af33684eea9bed4626e47246f3c998 libtasn1-debuginfo-4.13-3.el8_6.2.i686.rpm SHA-256: 5605496395e56abb36489fcaf7180548d695558a45e47080e7d4d3ca4ba3497b libtasn1-debuginfo-4.13-3.el8_6.2.i686.rpm SHA-256: 5605496395e56abb36489fcaf7180548d695558a45e47080e7d4d3ca4ba3497b libtasn1-debuginfo-4.13-3.el8_6.2.x86_64.rpm SHA-256: ad1ec1ac298df3e6dad70bfe79f7d3e20c390f6967f406cfa4afd692127b448d libtasn1-debuginfo-4.13-3.el8_6.2.x86_64.rpm SHA-256: ad1ec1ac298df3e6dad70bfe79f7d3e20c390f6967f406cfa4afd692127b448d libtasn1-debugsource-4.13-3.el8_6.2.i686.rpm SHA-256: 7a18db4262bf63087aca165f2bccb5baf1a9ee4daf84de9f75d7a5664741f9fd libtasn1-debugsource-4.13-3.el8_6.2.i686.rpm SHA-256: 7a18db4262bf63087aca165f2bccb5baf1a9ee4daf84de9f75d7a5664741f9fd libtasn1-debugsource-4.13-3.el8_6.2.x86_64.rpm SHA-256: 8d56d097ea41ffa230ff79105d62644ea5feb9228502b5a6d3852b756213e5ff libtasn1-debugsource-4.13-3.el8_6.2.x86_64.rpm SHA-256: 8d56d097ea41ffa230ff79105d62644ea5feb9228502b5a6d3852b756213e5ff libtasn1-devel-4.13-3.el8_6.2.i686.rpm SHA-256: 69da750be1d5c73f568e07ee5d11d1a2a2a64452ed1566f5ccd98fd559fc9f0f libtasn1-devel-4.13-3.el8_6.2.x86_64.rpm SHA-256: b8d1bc770812db5af9c72d5da75b61a49c6e6da02119af7d303920225837c15c libtasn1-tools-4.13-3.el8_6.2.x86_64.rpm SHA-256: 5e457102f84e4d8e76c23bc62ebde2225cc2a8bd7fda82af1f6a19b98f34134b libtasn1-tools-debuginfo-4.13-3.el8_6.2.i686.rpm SHA-256: 41d6ff0f68055a4e6c0113277fbf055d3394138648bf34967c7734d8a3da2e5e libtasn1-tools-debuginfo-4.13-3.el8_6.2.i686.rpm SHA-256:

Share this article