Junglewise Threat Intelligence

CVE-2026-3832: GnuTLS certificate revocation bypass in OCSP response handling

CVE-2026-3832 · Severity: low · CVSS 3.7 · Published 2026-04-30

Technologies: Red Hat Enterprise Linux, Gnutls, Red Hat OpenShift Container Platform. Vendors: Red Hat, Gnu.

Executive brief

GnuTLS is a widely used security library that helps applications establish encrypted connections. A flaw was found where the library incorrectly processes certificate status updates (OCSP), which are used to check if a security certificate has been cancelled or revoked. An attacker could exploit this to make a client accept a revoked or untrustworthy certificate, potentially allowing them to impersonate a legitimate service or intercept encrypted communications.

Technical details

A logic error exists in GnuTLS within the 'check_ocsp_response' function in 'lib/cert-session.c'. While the library correctly identifies the matching record index for a certificate using 'gnutls_ocsp_resp_check_crt', it incorrectly defaults to reading the certificate status from index 0 via 'gnutls_ocsp_resp_get_single' regardless of the actual match. A remote attacker can exploit this by providing a multi-record OCSP response where the first record indicates a 'good' status for an unrelated certificate, while the actual record for the server's revoked certificate appears later in the response. This results in the client incorrectly accepting a revoked certificate. Patches have been released by Red Hat for various Enterprise Linux versions.

Affected products

  • GNU GnuTLS 3.8.13-1.hum1, 3.8.10-4.el10_2
  • Red Hat Enterprise Linux 6.0, 7.0, 8.0, 9.0, 10.0, 10.2
  • Red Hat OpenShift Container Platform 4.0

Timeline

  • 2026-03-09: disclosed: Bug reported to Red Hat Bugzilla
  • 2026-04-30: advisory: Initial CVE publication
  • 2026-05-02: patched: Red Hat released security updates (RHSA-2026:13274)

References