CVE-2026-33845
EUVD-2026-2639230.04.2026, 18:16
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gnu | gnutls | - |
| redhat | openshift_container_platform | 4.0 |
| redhat | enterprise_linux | 6.0 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
| redhat | enterprise_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| gnutls |
| ||||||||||||||||
| gnutls-guile |
| ||||||||||||||||
| libgnutls-devel |
| ||||||||||||||||
| libgnutls-openssl-devel |
| ||||||||||||||||
| libgnutls-openssl27 |
| ||||||||||||||||
| libgnutls28 |
| ||||||||||||||||
| libgnutls28-32bit |
| ||||||||||||||||
| libgnutls30 |
| ||||||||||||||||
| libgnutls30-32bit |
| ||||||||||||||||
| libgnutls30-hmac |
| ||||||||||||||||
| libgnutls30-hmac-32bit |
| ||||||||||||||||
| libgnutlsxx-devel |
| ||||||||||||||||
| libgnutlsxx28 |
| ||||||||||||||||
| libgnutlsxx30 |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||
|---|---|---|---|---|---|
| gnutls |
| ||||
| gnutls-c |
| ||||
| gnutls-dane |
| ||||
| gnutls-devel |
| ||||
| gnutls-utils |
|
Amazon Linux Releases
Amazon Package | |||||
|---|---|---|---|---|---|
| gnutls |
| ||||
| gnutls-c++ |
| ||||
| gnutls-c++-debuginfo |
| ||||
| gnutls-dane |
| ||||
| gnutls-dane-debuginfo |
| ||||
| gnutls-debuginfo |
| ||||
| gnutls-debugsource |
| ||||
| gnutls-devel |
| ||||
| gnutls-utils |
| ||||
| gnutls-utils-debuginfo |
|
Common Weakness Enumeration
Vulnerability Media Exposure
References