Junglewise Threat Intelligence

CVE-2026-33846: GnuTLS heap buffer overflow in DTLS handshake reassembly

CVE-2026-33846 · Severity: high · CVSS 7.5 · Published 2026-05-04

Technologies: Red Hat Enterprise Linux 8, Gnutls, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10. Vendors: Red Hat.

Executive brief

A security vulnerability has been identified in GnuTLS, a widely used library that enables secure communications for applications and operating systems. An attacker can exploit this flaw to cause a system crash or potentially corrupt memory by sending specially crafted network packets during the initial connection phase. This could lead to a denial of service, impacting the availability of services that rely on GnuTLS for secure networking.

Technical details

A heap buffer overflow exists in the GnuTLS merge_handshake_packet() function within the DTLS handshake fragment reassembly logic. The vulnerability is caused by improper handling of length parameter inconsistency (CWE-130), where the implementation fails to validate that the message_length field remains consistent across all fragments of the same logical message. An attacker can send an initial small fragment to trigger a small buffer allocation, followed by larger fragments with inconsistent length values to perform an out-of-bounds write on the heap. This is remotely exploitable without authentication and can result in application crashes or potential code execution. Patches have been released by Red Hat for RHEL 8, 9, and 10.

Affected products

  • GnuTLS GnuTLS 3.8.13-1, 3.6.16-8.el8_10.6
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9
  • Red Hat Red Hat Enterprise Linux 10

Timeline

  • 2026-03-24: disclosed: Initial report in Red Hat Bugzilla
  • 2026-05-02: patched: Red Hat released initial security advisory RHSA-2026:13274
  • 2026-05-04: advisory: NVD published CVE-2026-33846

References

Related threats