Executive brief
GnuTLS is a widely used security library that enables encrypted communications for various applications and operating systems. A vulnerability in how it handles specific network handshake messages could allow a remote attacker to crash services using the library. This could lead to a denial of service, impacting the availability of secure web services and corporate infrastructure.
Technical details
An integer underflow vulnerability exists in GnuTLS during the reassembly of DTLS (Datagram Transport Layer Security) handshake fragments. The flaw is triggered when the library processes malformed fragments characterized by a zero length but a non-zero offset. This condition leads to an out-of-bounds read during the reassembly process. A remote, unauthenticated attacker can exploit this over the network by sending specially crafted DTLS packets. Successful exploitation can result in a denial of service (application crash) or potentially sensitive information disclosure from memory. Red Hat has released security updates (e.g., RHSA-2026:20611) to address this issue across its enterprise platforms.
Affected products
- GNU GnuTLS versions prior to 3.8.13-1.hum1
- Red Hat Enterprise Linux 6.0, 7.0, 8.0, 9.0, 10.0
- Red Hat OpenShift Container Platform 4.0
Timeline
- 2026-03-24: disclosed: Initial report in Red Hat Bugzilla
- 2026-04-30: advisory: NVD publication date
- 2026-05-02: patched: Red Hat released initial security advisory RHSA-2026:13274