CVE-2026-42010

high
Published 2026-05-07 Β· Modified 2026-05-26
CVSS v3
7.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
7.1

Description

RHSA-2026:20612: gnutls security update (Important)

Predictions

Exploit likelihood
80%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description gnutls: gnutls: Authentication Bypass via NUL Character in Username CVSS v3: 7.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 10gnutls-0:3.8.10-4.el10_2RHSA-2026:206132026-05-26T00:00:00Z Red Hat Enterprise Linux 8gnutls-0:3.6.16-8.el8_10.6RHSA-2026:206112026-05-26T00:00:00Z Red Hat Enterprise Linux…

Description

gnutls: gnutls: Authentication Bypass via NUL Character in Username

CVSS v3: 7.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 10gnutls-0:3.8.10-4.el10_2RHSA-2026:206132026-05-26T00:00:00Z
Red Hat Enterprise Linux 8gnutls-0:3.6.16-8.el8_10.6RHSA-2026:206112026-05-26T00:00:00Z
Red Hat Enterprise Linux 8gnutls-0:3.6.16-8.el8_10.6RHSA-2026:206112026-05-26T00:00:00Z
Red Hat Hardened Imagesgnutls-main-3.8.13-1.hum1RHSA-2026:132742026-05-02T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6gnutlsAffected
Red Hat Enterprise Linux 7gnutlsAffected
Red Hat Enterprise Linux 9gnutlsAffected
Red Hat OpenShift Container Platform 4rhcosAffected

Apply commands

bash fix
Apply RHSA-2026:20613 for Red Hat Enterprise Linux 10
yum update -y gnutls
# or:
dnf upgrade -y gnutls

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 6Affected
redhatRed Hat Enterprise Linux 7Affected
redhatRed Hat Enterprise Linux 9Affected
redhatRed Hat OpenShift Container Platform 4Affected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
windows Windows Affected 1 release
VersionStatusFixed in
β€” Affected β€”
redhat Red Hat Mixed 7 releases
VersionStatusFixed in
10.0 Affected β€”
9.0 Affected β€”
9 Fixed β€”
8.0 Affected β€”
8 Fixed β€”
7.0 Affected β€”
6.0 Affected β€”
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 3.8.9-3+deb13u4
sid Fixed 3.8.13-1
forky Fixed 3.8.13-1
bullseye Fixed 3.7.1-5+deb11u10
bookworm Fixed 3.7.9-2+deb12u7

Application impact

VendorProductVersionsFixed
gnugnutls-
redhat redhathardened_images-
redhat redhatopenshift_container_platform4.0

References

CWEs

CWE-626

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.