Executive brief
GnuTLS is a widely used security library that enables secure communications over the internet. A flaw in how it handles specific connection requests allows a remote, unauthenticated attacker to crash servers using this library. This results in a denial-of-service (DoS) condition, potentially disrupting business operations and service availability.
Technical details
A NULL pointer dereference exists in GnuTLS within the PSK (Pre-Shared Key) binder verification logic. When a server receives a ClientHello message referencing a previously issued session ticket, the '_gnutls_get_cred' function may return a NULL pointer for PSK credentials. If the attacker provides an invalid PSK binder value, the server attempts to dereference this NULL pointer in 'server_recv_params' while attempting to access 'pskcred->binder_algo'. This vulnerability can be exploited by a remote, unauthenticated attacker to crash the server process. Red Hat has released patches for affected Hardened Images (RHSA-2026:7477).
Affected products
- GnuTLS GnuTLS 3.8.12-1.1.hum1 and earlier
- Red Hat Red Hat Hardened Images gnutls-3.8.12-1.1.hum1
Timeline
- 2026-01-29: disclosed: Reported via Red Hat Bugzilla
- 2026-04-09: advisory: NVD publication date
- 2026-04-10: patched: Red Hat released security advisory RHSA-2026:7477
References
- https://catalog.redhat.com/software/containers/
- https://access.redhat.com/downloads/content/package-browser/
- https://access.redhat.com/errata/RHSA-2026:7477
- https://access.redhat.com/security/cve/CVE-2026-1584
- https://bugzilla.redhat.com/show_bug.cgi?id=2435258
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1584.json