Executive brief
glib-networking is a software component used by many Linux applications to handle secure network connections. A flaw in how it verifies security certificates allows a remote attacker to send a specially crafted certificate that triggers an infinite loop. This causes the affected application to consume 100% of the processor's power, effectively freezing the service and making it unavailable to legitimate users.
Technical details
A vulnerability exists in the glib-networking GnuTLS backend within the certificate verification path. When processing a peer-supplied certificate chain, the code in `gtlsdatabase-gnutls.c` fails to detect circular issuer relationships. An attacker can present a crafted chain where certificates mutually reference each other as issuers, causing the `convert_certificate_chain_to_gnutls` function to enter an infinite loop during traversal. This results in a permanent hang of the handshake thread and 100% CPU utilization. The issue affects versions utilizing the GnuTLS backend when certificate verification is performed (e.g., a client connecting to a malicious server or a server verifying client certificates).
Affected products
- GNOME glib-networking 2.80.0-3.el10
Timeline
- 2026-05-04: other: Reported to Red Hat by Aisle Research
- 2026-05-28: advisory: CVE-2026-10028 published