VYPR

rpm package

almalinux/gnutls-fips

pkg:rpm/almalinux/gnutls-fips

Vulnerabilities (12)

  • CVE-2026-42009HigMay 18, 2026
    affected < 3.8.10-4.el10_2fixed 3.8.10-4.el10_2

    A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequen

  • CVE-2026-42011HigMay 7, 2026
    affected < 3.8.10-4.el10_2fixed 3.8.10-4.el10_2

    A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during

  • CVE-2026-42010HigMay 7, 2026
    affected < 3.8.10-4.el10_2fixed 3.8.10-4.el10_2

    A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authe

  • CVE-2026-33846HigMay 4, 2026
    affected < 3.8.10-4.el10_2fixed 3.8.10-4.el10_2

    A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length

  • CVE-2026-3833MedApr 30, 2026
    affected < 3.8.10-4.el10_2fixed 3.8.10-4.el10_2

    A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can explo

  • CVE-2026-33845HigApr 30, 2026
    affected < 3.8.10-4.el10_2fixed 3.8.10-4.el10_2

    A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of

  • CVE-2025-14831MedFeb 9, 2026
    affected < 3.8.10-3.el10_1fixed 3.8.10-3.el10_1

    A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).

  • CVE-2025-9820MedJan 26, 2026
    affected < 3.8.10-3.el10_1fixed 3.8.10-3.el10_1

    A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a fixed-size stack buffer. This programming error c

  • CVE-2025-6395MedJul 10, 2025
    affected < 3.8.9-9.el10_0.14fixed 3.8.9-9.el10_0.14

    A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite().

  • CVE-2025-32990MedJul 10, 2025
    affected < 3.8.9-9.el10_0.14fixed 3.8.9-9.el10_0.14

    A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory

  • CVE-2025-32989MedJul 10, 2025
    affected < 3.8.9-9.el10_0.14fixed 3.8.9-9.el10_0.14

    A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to create a certificate containing a malformed SCT extensi

  • CVE-2025-32988MedJul 10, 2025
    affected < 3.8.9-9.el10_0.14fixed 3.8.9-9.el10_0.14

    A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS will call asn1_delete_structure()