Medium severity5.9NVD Advisory· Published Apr 1, 2019· Updated Jun 17, 2026
CVE-2019-3836
CVE-2019-3836
Description
It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
21- cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*
- Range: >=3.6.3 <3.6.7
- osv-coords16 versionspkg:apk/chainguard/gnutlspkg:apk/chainguard/gnutls-c%2B%2Bpkg:apk/chainguard/gnutls-c++pkg:apk/chainguard/gnutls-devpkg:apk/chainguard/gnutls-docpkg:apk/chainguard/gnutls-utilspkg:apk/wolfi/gnutlspkg:apk/wolfi/gnutls-c%2B%2Bpkg:apk/wolfi/gnutls-c++pkg:apk/wolfi/gnutls-devpkg:apk/wolfi/gnutls-docpkg:apk/wolfi/gnutls-utilspkg:rpm/opensuse/gnutls&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/gnutls&distro=openSUSE%20Tumbleweedpkg:rpm/suse/gnutls&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015pkg:rpm/suse/gnutls&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015
< 0+ 15 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 3.6.7-lp150.9.1
- (no CPE)range: < 3.7.2-1.2
- (no CPE)range: < 3.6.7-6.8.1
- (no CPE)range: < 3.6.7-6.8.1
- Range: fixed in gnutls 3.6.7
Patches
Vulnerability mechanics
References
8- gitlab.com/gnutls/gnutls/issues/704nvdExploitIssue TrackingThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2019-05/msg00017.htmlnvdMailing ListThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- security.gentoo.org/glsa/201904-14nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20190502-0005/nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2019:3600nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A3ETBUFBB4G7AITAOUYPGXVMBGVXKUAN/nvd
- usn.ubuntu.com/3999-1/nvd
News mentions
0No linked articles in our index yet.