CVE-2026-42010
EUVD-2026-2835407.05.2026, 12:16
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gnu | gnutls | - |
| redhat | hardened_images | - |
| redhat | openshift_container_platform | 4.0 |
| redhat | enterprise_linux | 6.0 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
| redhat | enterprise_linux | 10.0 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:3.8.10-4.el10_2 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:3.8.9-9.el10_0.19 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8 | 0:3.6.16-8.el8_10.6 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 0:3.6.14-10.el8_4.1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 0:4.13-3.el8_4.1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | 0:3.6.14-10.el8_4.1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | 0:4.13-3.el8_4.1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | 0:3.6.16-5.el8_6.5 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | 0:4.13-3.el8_6.2 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | 0:3.6.16-5.el8_6.5 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | 0:4.13-3.el8_6.2 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | 0:3.6.16-7.el8_8.4 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | 0:4.13-4.el8_8.1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | 0:3.6.16-7.el8_8.4 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | 0:4.13-4.el8_8.1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9 | 0:3.8.10-4.el9_8 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | 0:3.7.6-21.el9_2.7 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | 0:3.8.3-4.el9_4.6 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 0:3.8.3-6.el9_6.4 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 4.19.9.6.202607151909-0 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 4.20.9.6.202607010620-0 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 4.21.9.6.202607011303-0 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 4.22.9.8.202606301732-0 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat AI Inference Server 3.2 | 1782951051 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat AI Inference Server 3.2 | 1782951012 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat AI Inference Server 3.2 | 1782951244 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Discovery 2 | 1782159791 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Discovery 2 | 1782166952 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Hardened Images | 3.8.13-1.hum1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Update Infrastructure 5 | 1781525684 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Update Infrastructure 5 | 1781525671 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Update Infrastructure 5 | 1781525693 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Update Infrastructure 5 | 1781525739 ≤ 𝑥 < * | ADP |
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| gnutls |
| ||||||||||||
| gnutls-guile |
| ||||||||||||
| libgnutls-devel |
| ||||||||||||
| libgnutls30 |
| ||||||||||||
| libgnutls30-32bit |
| ||||||||||||
| libgnutls30-hmac |
| ||||||||||||
| libgnutls30-hmac-32bit |
| ||||||||||||
| libgnutlsxx-devel |
| ||||||||||||
| libgnutlsxx28 |
| ||||||||||||
| libgnutlsxx30 |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| gnutls |
| ||||||||||||
| gnutls-c |
| ||||||||||||
| gnutls-dane |
| ||||||||||||
| gnutls-devel |
| ||||||||||||
| gnutls-utils |
| ||||||||||||
| libtasn1 |
| ||||||||||||
| libtasn1-devel |
| ||||||||||||
| libtasn1-tools |
|
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| gnutls |
| ||
| gnutls-c++ |
| ||
| gnutls-c++-debuginfo |
| ||
| gnutls-dane |
| ||
| gnutls-dane-debuginfo |
| ||
| gnutls-debuginfo |
| ||
| gnutls-debugsource |
| ||
| gnutls-devel |
| ||
| gnutls-utils |
| ||
| gnutls-utils-debuginfo |
|
Common Weakness Enumeration
- CWE-170 - Improper Null TerminationThe software does not terminate or incorrectly terminates a string or array with a null character or equivalent terminator.
- CWE-626 - Null Byte Interaction Error (Poison Null Byte)The product does not properly handle null bytes or NUL characters when passing data between different representations or components.
References