Executive brief
GnuTLS is a widely used security library that helps applications establish secure, encrypted connections. A flaw was found where the library takes different amounts of time to process certain encrypted data, which could allow a remote attacker to slowly piece together sensitive information. While difficult to exploit, this could lead to the unauthorized disclosure of private data.
Technical details
A timing side-channel vulnerability (CWE-208) exists in GnuTLS due to a non-constant-time PKCS#7 padding check during decryption. By observing minute differences in the time it takes for the library to respond to decryption requests with varying padding, a remote attacker can potentially perform a padding oracle-style attack to recover plaintext information. The attack requires a high degree of complexity and network stability to measure timing differences accurately. Red Hat has released patches for affected GnuTLS packages in RHEL 10.
Affected products
- GnuTLS gnutls 3.8.10-4.el10_2
Timeline
- 2026-05-26: patched: Red Hat released security update RHSA-2026:20613
- 2026-06-01: disclosed: CVE published in NVD dataset