Search CVE reports


Toggle filters

11 – 20 of 71 results


CVE-2026-42009

Medium priority
Needs evaluation

The comparator function used for ordering DTLS packets by sequence numbers did not follow qsort comparator contracts in case of packets with duplicate sequence numbers, which could lead to undefined behaviour.

1 affected package

gnutls28

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls28 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-3833

Medium priority
Needs evaluation

A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees`...

1 affected package

gnutls28

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls28 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-33845

Medium priority
Needs evaluation

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable...

1 affected package

gnutls28

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls28 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-1584

High priority
Not affected

A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value during the TLS handshake. This can...

1 affected package

gnutls28

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls28 Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-14831

Medium priority

Some fixes available 3 of 6

A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of...

1 affected package

gnutls28

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls28 Not affected Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2025-9820

Low priority

Some fixes available 3 of 7

A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a...

1 affected package

gnutls28

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls28 Not affected Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2025-6395

Medium priority

Some fixes available 6 of 7

A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite().

1 affected package

gnutls28

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls28 Fixed Fixed Fixed Fixed Not affected
Show less packages

CVE-2025-32990

Medium priority

Some fixes available 8 of 9

A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause...

1 affected package

gnutls28

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls28 Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-32989

Medium priority

Some fixes available 5 of 6

A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to...

1 affected package

gnutls28

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls28 Fixed Fixed Fixed Not affected Not affected
Show less packages

CVE-2025-32988

Medium priority

Some fixes available 7 of 8

A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or...

1 affected package

gnutls28

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls28 Fixed Fixed Fixed Fixed Fixed
Show less packages