Executive brief
A vulnerability has been identified in GnuTLS, a widely used security library that enables secure communications for various applications and operating systems. An attacker can exploit this flaw by providing a specially crafted digital certificate, causing the system to consume excessive processor and memory resources. This can lead to a denial-of-service (DoS) condition, potentially making affected services unavailable to legitimate users.
Technical details
A flaw was found in GnuTLS's certificate verification logic (CWE-407: Inefficient Algorithmic Complexity). The vulnerability is triggered when the library processes malicious X.509 certificates that contain an excessive number of name constraints and Subject Alternative Names (SANs). An unauthenticated remote attacker can provide such a certificate during a TLS handshake or other verification processes to exhaust CPU and memory resources on the target system. This results in a denial of service. Red Hat has released several security advisories (e.g., RHSA-2026:13812) providing backported patches for affected Enterprise Linux and OpenShift components.
Affected products
- GnuTLS GnuTLS
- Red Hat Enterprise Linux 8
- Red Hat OpenShift Container Platform 4.10
- Red Hat OpenShift Container Platform 4.11
- Red Hat OpenShift Container Platform 4.12
Timeline
- 2025-02-09: disclosed: CVE assigned/initial disclosure date
- 2026-02-09: advisory: NVD publication date
- 2026-05-05: patched: Red Hat released patches for RHEL-8 based Middleware Containers
References
- https://access.redhat.com/errata/RHSA-2026:13812
- https://access.redhat.com/errata/RHSA-2026:16008
- https://access.redhat.com/errata/RHSA-2026:16009
- https://access.redhat.com/errata/RHSA-2026:16174
- https://access.redhat.com/errata/RHSA-2026:25096
- https://access.redhat.com/errata/RHSA-2026:3477
- https://access.redhat.com/errata/RHSA-2026:4188