Junglewise Threat Intelligence

CVE-2026-5419: GnuTLS non-constant-time PKCS#7 padding check

CVE-2026-5419 · Severity: low · CVSS 3.7 · Published 2026-06-01

Technologies: Gnutls.

Executive brief

GnuTLS is a widely used security library that helps applications establish secure, encrypted connections. A flaw was found where the library takes different amounts of time to process certain encrypted data, which could allow a remote attacker to slowly piece together sensitive information. While difficult to exploit, this could lead to the unauthorized disclosure of private data.

Technical details

A timing side-channel vulnerability (CWE-208) exists in GnuTLS due to a non-constant-time PKCS#7 padding check during decryption. By observing minute differences in the time it takes for the library to respond to decryption requests with varying padding, a remote attacker can potentially perform a padding oracle-style attack to recover plaintext information. The attack requires a high degree of complexity and network stability to measure timing differences accurately. Red Hat has released patches for affected GnuTLS packages in RHEL 10.

Affected products

  • GnuTLS gnutls 3.8.10-4.el10_2

Timeline

  • 2026-05-26: patched: Red Hat released security update RHSA-2026:20613
  • 2026-06-01: disclosed: CVE published in NVD dataset

References