[CLSA-2026:1780484200] gnutls: Fix of 8 CVEs
Type:
security
Severity:
Important
Release date:
2026-06-03 10:57:05 UTC
Description:
- CVE-2026-33846: fix heap buffer overflow in DTLS handshake fragment reassembly by validating message-length consistency and bounding the fragment write against the destination buffer capacity - CVE-2026-42009: fix undefined behaviour in DTLS packet ordering by making the handshake_compare qsort comparator return 0 for equal sequence numbers - CVE-2026-42011: fix name constraints bypass by no longer short-circuiting the intersection of an empty permitted set, so later permitted constraints are still enforced - CVE-2026-42012: fix certificate verification bypass by making URI and SRV subjectAltName entries preclude the legacy CN fallback hostname check - CVE-2026-42013: fix certificate verification bypass by preventing CN and DN-email fallback when a subjectAltName entry is oversized - CVE-2026-5260: fix heap overread in RSA key exchange by rejecting a ciphertext whose size does not match the RSA modulus - CVE-2026-42014: fix use-after-free and leak in gnutls_pkcs11_token_set_pin when changing the security officer PIN - CVE-2026-42015: fix off-by-one out-of-bounds write when appending an element to a PKCS#12 bag that already holds the maximum number of elements
Updated packages:
  • gnutls-3.8.3-9.el9_6.tuxcare.1.els6.i686.rpm
    sha:4ef6310abb9013a48d9c93a2ba2709a9dd6f46d84a39befd8c7560776e84ffa5
  • gnutls-3.8.3-9.el9_6.tuxcare.1.els6.x86_64.rpm
    sha:8b5e1ad5a321f2085d3a473efd9af6dedc02ecdcc679e2ef4e5c33aba3f6051e
  • gnutls-c++-3.8.3-9.el9_6.tuxcare.1.els6.i686.rpm
    sha:62fc1206d55f9bb684420c0fb4eceedd1abebca46be766ddbfe2bcd9eda3560d
  • gnutls-c++-3.8.3-9.el9_6.tuxcare.1.els6.x86_64.rpm
    sha:b972462c2e68b01e0569a7821dc19d2eae49817affeff85f3fdf881f34738edf
  • gnutls-dane-3.8.3-9.el9_6.tuxcare.1.els6.i686.rpm
    sha:4e6f8beb7eb3f4ae30f9699c9eacfc943c1a20a275220a12e6e32a61dd6ef243
  • gnutls-dane-3.8.3-9.el9_6.tuxcare.1.els6.x86_64.rpm
    sha:2c1b229415b17914a732a728321b52eea1975df5f970814c79b1483da029f496
  • gnutls-devel-3.8.3-9.el9_6.tuxcare.1.els6.i686.rpm
    sha:585f72ce3b5be9a3f81c924832161fed07f9170d63e43892ebf62524126503f8
  • gnutls-devel-3.8.3-9.el9_6.tuxcare.1.els6.x86_64.rpm
    sha:afa9111c4a645e05ff8d2cd8ec0f9f1a0e124422a7572a0c19f8397502f71d6c
  • gnutls-utils-3.8.3-9.el9_6.tuxcare.1.els6.x86_64.rpm
    sha:12dcacc4f2d9fd605e347d3099301a1ff6869f938499f4587bb4331a005522dc
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.