CVE-2026-5260

high
Published 2026-05-26 Β· Modified 2026-05-26
CVSS v3
8.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
8.2

Description

RHSA-2026:20612: gnutls security update (Important)

Predictions

Exploit likelihood
88%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description gnutls: gnutls: Information disclosure via heap overread in RSA key exchange CVSS v3: 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 10gnutls-0:3.8.10-4.el10_2RHSA-2026:206132026-05-26T00:00:00Z Red Hat Enterprise Linux 8gnutls-0:3.6.16-8.el8_10.6RHSA-2026:206112026-05-26T00:00:00Z Red Hat Enterprise…

Description

gnutls: gnutls: Information disclosure via heap overread in RSA key exchange

CVSS v3: 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 10gnutls-0:3.8.10-4.el10_2RHSA-2026:206132026-05-26T00:00:00Z
Red Hat Enterprise Linux 8gnutls-0:3.6.16-8.el8_10.6RHSA-2026:206112026-05-26T00:00:00Z
Red Hat Enterprise Linux 8gnutls-0:3.6.16-8.el8_10.6RHSA-2026:206112026-05-26T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6gnutlsOut of support scope
Red Hat Enterprise Linux 7gnutlsAffected
Red Hat Enterprise Linux 9gnutlsAffected
Red Hat Hardened ImagesgnutlsAffected
Red Hat OpenShift Container Platform 4rhcosAffected

Apply commands

bash fix
Apply RHSA-2026:20613 for Red Hat Enterprise Linux 10
yum update -y gnutls
# or:
dnf upgrade -y gnutls

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 7Affected
redhatRed Hat Enterprise Linux 9Affected
redhatRed Hat Hardened ImagesAffected
redhatRed Hat OpenShift Container Platform 4Affected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
windows Windows Affected 1 release
VersionStatusFixed in
β€” Affected β€”
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 3.8.9-3+deb13u4
sid Fixed 3.8.13-1
forky Fixed 3.8.13-1
bullseye Fixed 3.7.1-5+deb11u10
bookworm Fixed 3.7.9-2+deb12u7
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”

References

CWEs

CWE-1284

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.