Executive brief
GnuTLS is a widely used security library that helps applications establish encrypted connections. A flaw was found where the library incorrectly processes certificate status updates (OCSP), which are used to check if a security certificate has been cancelled or revoked. An attacker could exploit this to make a client accept a revoked or untrustworthy certificate, potentially allowing them to impersonate a legitimate service or intercept encrypted communications.
Technical details
A logic error exists in GnuTLS within the 'check_ocsp_response' function in 'lib/cert-session.c'. While the library correctly identifies the matching record index for a certificate using 'gnutls_ocsp_resp_check_crt', it incorrectly defaults to reading the certificate status from index 0 via 'gnutls_ocsp_resp_get_single' regardless of the actual match. A remote attacker can exploit this by providing a multi-record OCSP response where the first record indicates a 'good' status for an unrelated certificate, while the actual record for the server's revoked certificate appears later in the response. This results in the client incorrectly accepting a revoked certificate. Patches have been released by Red Hat for various Enterprise Linux versions.
Affected products
- GNU GnuTLS 3.8.13-1.hum1, 3.8.10-4.el10_2
- Red Hat Enterprise Linux 6.0, 7.0, 8.0, 9.0, 10.0, 10.2
- Red Hat OpenShift Container Platform 4.0
Timeline
- 2026-03-09: disclosed: Bug reported to Red Hat Bugzilla
- 2026-04-30: advisory: Initial CVE publication
- 2026-05-02: patched: Red Hat released security updates (RHSA-2026:13274)