Security News

Cybersecurity news aggregator

🔄
INFO Updates Red Hat Errata

RHSA-2026:30850: Important: gnutls and libtasn1 security update

  • What: Security update for gnutls and libtasn1
  • Impact: Red Hat Enterprise Linux 8.8 systems
Read Full Article →

Red Hat Product Errata RHSA-2026:30850 - Security Advisory Issued: 2026-06-29 Updated: 2026-06-29 RHSA-2026:30850 - Security Advisory Overview Updated Packages Synopsis Important: gnutls and libtasn1 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for multiple packages is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS. Security Fix(es): libtasn1: Inefficient DER Decoding in libtasn1 Leading to Potential Remote DoS (CVE-2024-12133) gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification (CVE-2025-14831) gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison (CVE-2026-3833) gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment (CVE-2026-33845) gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly (CVE-2026-33846) gnutls: Fix qsort comparator in DTLS reassembly (CVE-2026-42009) gnutls: gnutls: Authentication Bypass via NUL Character in Username (CVE-2026-42010) gnutls: gnutls: Security bypass due to incorrect name constraint handling (CVE-2026-42011) gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs (CVE-2026-42012) gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name (CVE-2026-42013) gnutls: gnutls: Information disclosure via heap overread in RSA key exchange (CVE-2026-5260) gnutls: Fix use-after-free in gnutls_pkcs11_token_set_pin (CVE-2026-42014) gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling (CVE-2026-42015) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8 x86_64 Red Hat Enterprise Linux Server - TUS 8.8 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64 Fixes BZ - 2344611 - CVE-2024-12133 libtasn1: Inefficient DER Decoding in libtasn1 Leading to Potential Remote DoS BZ - 2423177 - CVE-2025-14831 gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification BZ - 2445763 - CVE-2026-3833 gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison BZ - 2450624 - CVE-2026-33845 gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment BZ - 2450625 - CVE-2026-33846 gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly BZ - 2467279 - CVE-2026-42009 gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability BZ - 2467289 - CVE-2026-42010 gnutls: gnutls: Authentication Bypass via NUL Character in Username BZ - 2467437 - CVE-2026-42011 gnutls: gnutls: Security bypass due to incorrect name constraint handling BZ - 2467441 - CVE-2026-42012 gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs BZ - 2467448 - CVE-2026-42013 gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name BZ - 2467450 - CVE-2026-5260 gnutls: gnutls: Information disclosure via heap overread in RSA key exchange BZ - 2467451 - CVE-2026-42014 gnutls: gnutls: Use-after-free in gnutls_pkcs11_token_set_pin BZ - 2467678 - CVE-2026-42015 gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling CVEs CVE-2024-12133 CVE-2025-14831 CVE-2026-3833 CVE-2026-5260 CVE-2026-33845 CVE-2026-33846 CVE-2026-42009 CVE-2026-42010 CVE-2026-42011 CVE-2026-42012 CVE-2026-42013 CVE-2026-42014 CVE-2026-42015 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8 SRPM gnutls-3.6.16-7.el8_8.4.src.rpm SHA-256: b02e422a468c67fa45eae104726ae1ef432937a12e6db7aa776377d073e8baf0 libtasn1-4.13-4.el8_8.1.src.rpm SHA-256: 03e27f00d0e800feb58c366560da02ec7661dd754de24f5d821fe2c91e373039 x86_64 gnutls-3.6.16-7.el8_8.4.i686.rpm SHA-256: 107a30e7e700eecc2af6c10f271f7aaf298d9a94d97aaac2caef67576746ced8 gnutls-3.6.16-7.el8_8.4.x86_64.rpm SHA-256: 789d64fc709e87c299e124fdf734323341adc3b1feda9f22c6e3f7e68f3100ca gnutls-c++-3.6.16-7.el8_8.4.i686.rpm SHA-256: 2825303b2945b08c01973aef3ca10d6ccbf40159779729a1af3fc2d6fb0d3aa4 gnutls-c++-3.6.16-7.el8_8.4.x86_64.rpm SHA-256: 855eb0cd11023353686c60dc26f67a7974a9fcebfa0b7f2850af0106caff23e6 gnutls-c++-debuginfo-3.6.16-7.el8_8.4.i686.rpm SHA-256: ea19d3923ee0cf59bd5603ed0d86e0ca8f5c631ed433bb74fb2781ee86754704 gnutls-c++-debuginfo-3.6.16-7.el8_8.4.i686.rpm SHA-256: ea19d3923ee0cf59bd5603ed0d86e0ca8f5c631ed433bb74fb2781ee86754704 gnutls-c++-debuginfo-3.6.16-7.el8_8.4.x86_64.rpm SHA-256: 8c63573ad1876cab9135dafdd3ebe063963f41738356bc9284c1e0548c4fb126 gnutls-c++-debuginfo-3.6.16-7.el8_8.4.x86_64.rpm SHA-256: 8c63573ad1876cab9135dafdd3ebe063963f41738356bc9284c1e0548c4fb126 gnutls-dane-3.6.16-7.el8_8.4.i686.rpm SHA-256: f1333941993576f8783b091a4e95462991a602aa61035569e18f4bb035483b2b gnutls-dane-3.6.16-7.el8_8.4.x86_64.rpm SHA-256: 6fe12cadfc69ec7328a1cdb303c37d880f465b6506eb8fb91c4b387bb6aff561 gnutls-dane-debuginfo-3.6.16-7.el8_8.4.i686.rpm SHA-256: d04b773437d7e5ceace5b1cfba9767b798417235ec3d9decd93af0e934680e5e gnutls-dane-debuginfo-3.6.16-7.el8_8.4.i686.rpm SHA-256: d04b773437d7e5ceace5b1cfba9767b798417235ec3d9decd93af0e934680e5e gnutls-dane-debuginfo-3.6.16-7.el8_8.4.x86_64.rpm SHA-256: 284b70794d66a27deb09f2a5d2765b2a1a5a4e3979769c4f7d8ace29273b3d95 gnutls-dane-debuginfo-3.6.16-7.el8_8.4.x86_64.rpm SHA-256: 284b70794d66a27deb09f2a5d2765b2a1a5a4e3979769c4f7d8ace29273b3d95 gnutls-debuginfo-3.6.16-7.el8_8.4.i686.rpm SHA-256: eed56148e5142c4776fd3f4b8907857fe9ad5e39021a9ae21e9f8d0519271f88 gnutls-debuginfo-3.6.16-7.el8_8.4.i686.rpm SHA-256: eed56148e5142c4776fd3f4b8907857fe9ad5e39021a9ae21e9f8d0519271f88 gnutls-debuginfo-3.6.16-7.el8_8.4.x86_64.rpm SHA-256: 26337e207ea197994ba8bd609bd12e28f9c923fe5dd976adec64a2fb94ddcda7 gnutls-debuginfo-3.6.16-7.el8_8.4.x86_64.rpm SHA-256: 26337e207ea197994ba8bd609bd12e28f9c923fe5dd976adec64a2fb94ddcda7 gnutls-debugsource-3.6.16-7.el8_8.4.i686.rpm SHA-256: ff386b1250640d90a5516b6f2d1437627882f3ced2dd7d88caf7649d4d48bafa gnutls-debugsource-3.6.16-7.el8_8.4.i686.rpm SHA-256: ff386b1250640d90a5516b6f2d1437627882f3ced2dd7d88caf7649d4d48bafa gnutls-debugsource-3.6.16-7.el8_8.4.x86_64.rpm SHA-256: e2ca379cc4dda7cc34d16d7a54f08515dd4b18375c707028ef800ad51084839e gnutls-debugsource-3.6.16-7.el8_8.4.x86_64.rpm SHA-256: e2ca379cc4dda7cc34d16d7a54f08515dd4b18375c707028ef800ad51084839e gnutls-devel-3.6.16-7.el8_8.4.i686.rpm SHA-256: 00293ead30961488d10737b0092baa9ffe038a8bd6943c3eeb5556626eb4f6ed gnutls-devel-3.6.16-7.el8_8.4.x86_64.rpm SHA-256: 387e68f35b2de34e985cc517bb2c311576d25acee2719785f9bac16d2cc55693 gnutls-utils-3.6.16-7.el8_8.4.x86_64.rpm SHA-256: 5ad55de36637aa61246377c4d0b996872be529d492746609674d2b8da3ad5874 gnutls-utils-debuginfo-3.6.16-7.el8_8.4.i686.rpm SHA-256: 205834aa4a9d57ab8d7b0d026f0bf09b52d561cd3b069b0b219b61c3742c1bc5 gnutls-utils-debuginfo-3.6.16-7.el8_8.4.i686.rpm SHA-256: 205834aa4a9d57ab8d7b0d026f0bf09b52d561cd3b069b0b219b61c3742c1bc5 gnutls-utils-debuginfo-3.6.16-7.el8_8.4.x86_64.rpm SHA-256: 90d1c8487d9e5cec411be045d714606c6551d96760f60e016c9c854ba519b226 gnutls-utils-debuginfo-3.6.16-7.el8_8.4.x86_64.rpm SHA-256: 90d1c8487d9e5cec411be045d714606c6551d96760f60e016c9c854ba519b226 libtasn1-4.13-4.el8_8.1.i686.rpm SHA-256: e76ab495ec875becaec792790af2c66da96b3087ad771b6292b99b756cacda7d libtasn1-4.13-4.el8_8.1.x86_64.rpm SHA-256: 957cae27ba69e57455da4d91c801b6419acdc681aa686eb1a84fa39938ff79ec libtasn1-debuginfo-4.13-4.el8_8.1.i686.rpm SHA-256: 3daf0827f5ef1235b19d6fd2154633b6bee646c192fd94bdc215f67a7223fac7 libtasn1-debuginfo-4.13-4.el8_8.1.i686.rpm SHA-256: 3daf0827f5ef1235b19d6fd2154633b6bee646c192fd94bdc215f67a7223fac7 libtasn1-debuginfo-4.13-4.el8_8.1.x86_64.rpm SHA-256: 641b43d55e00a4f5098bf7b6590c45d72521c9ca3982852e64884190acbf7288 libtasn1-debuginfo-4.13-4.el8_8.1.x86_64.rpm SHA-256: 641b43d55e00a4f5098bf7b6590c45d72521c9ca3982852e64884190acbf7288 libtasn1-debugsource-4.13-4.el8_8.1.i686.rpm SHA-256: c98c01783317646ec7fc23d4b33f6ec64b53145c8e8c32b9557f526151b2cc48 libtasn1-debugsource-4.13-4.el8_8.1.i686.rpm SHA-256: c98c01783317646ec7fc23d4b33f6ec64b53145c8e8c32b9557f526151b2cc48 libtasn1-debugsource-4.13-4.el8_8.1.x86_64.rpm SHA-256: 68e240bad8ff546af4f4a3349b5949699d07f3028d901ec98c032cc5a9f1f13e libtasn1-debugsource-4.13-4.el8_8.1.x86_64.rpm SHA-256: 68e240bad8ff546af4f4a3349b5949699d07f3028d901ec98c032cc5a9f1f13e libtasn1-devel-4.13-4.el8_8.1.i686.rpm SHA-256: bae20211b57b01ea6415de750bbd8303c24bc430c1f23e0193202337fc90bbaf libtasn1-devel-4.13-4.el8_8.1.x86_64.rpm SHA-256: 0e819f373a56a0791286440756c83b35f24549aff8b1467a420e29f0d3b9521b libtasn1-tools-4.13-4.el8_8.1.x86_64.rpm SHA-256: bef2c2c6cd448fc036e2eace1b0735cac8951d728c240c582bc3a959c83eb0a2 libtasn1-tools-debu

Share this article