Description
A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected products
- gnu / gnutls
- RedHat / enterprise_linux10.0 – 10.0
- RedHat / enterprise_linux8.0 – 8.0
- RedHat / enterprise_linux9.0 – 9.0
- RedHat / enterprise_linux6.0 – 6.0
- RedHat / enterprise_linux7.0 – 7.0
- RedHat / hardened_images
- RedHat / openshift_container_platform4.0 – 4.0
References
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:13274
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:20612
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:20613
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:26319
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:26409
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:29197
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:58981
- VENDOR_ADVISORYhttps://access.redhat.com/security/cve/CVE-2026-3832
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=2445762
- MISChttps://gitlab.com/gnutls/gnutls/-/issues/1801
Updated 8m ago · 8 sources