[CLSA-2026:1779881448] gnutls: Fix of CVE-2026-42010
Type:
security
Severity:
Critical
Release date:
2026-05-27 11:31:21 UTC
Description:
- CVE-2026-42010: RSA-PSK server truncated PSK identity at an embedded NUL byte during _gnutls_psk_pwd_find_entry lookup, allowing authentication bypass; use info->username_len instead of strlen(info->username)
Updated packages:
  • gnutls-3.6.16-4.el8.tuxcare.els11.i686.rpm
    sha:ee23543896e7c3681065fb99ec1b24ca04013bc97b363cd52a4775b8a7bc21b8
  • gnutls-3.6.16-4.el8.tuxcare.els11.x86_64.rpm
    sha:523ce2b575f5d3814ddd806905915100ebc7e03eb3f187bd3b7322fc004b0956
  • gnutls-c++-3.6.16-4.el8.tuxcare.els11.i686.rpm
    sha:117b6b941f12e8e9a474a24d1819892cada08cf89241b7c6acd61a1cf6a9dd07
  • gnutls-c++-3.6.16-4.el8.tuxcare.els11.x86_64.rpm
    sha:ea26e6989eb293efcffe87ddb5f8227470a5594f5ecf125840f6671cc58ba2ca
  • gnutls-dane-3.6.16-4.el8.tuxcare.els11.i686.rpm
    sha:a3df66ee6c52c950cec454b049e05ebcec2281cf5e1b2500236156cab35f0dac
  • gnutls-dane-3.6.16-4.el8.tuxcare.els11.x86_64.rpm
    sha:890c7c91a1a0c1d75dcef2f4c8aebc29bf6394370cb56d14b5bc93d7b6b598b2
  • gnutls-devel-3.6.16-4.el8.tuxcare.els11.i686.rpm
    sha:a81499206ae61052d642d9f7db34ca23a1e6f5b531ff979fc98d37ddf946378c
  • gnutls-devel-3.6.16-4.el8.tuxcare.els11.x86_64.rpm
    sha:9fbc81a03b1702347c954644c54ef2ab08211a5ac9c8703ecd32730941022de7
  • gnutls-utils-3.6.16-4.el8.tuxcare.els11.x86_64.rpm
    sha:003e6ba2585bcd2c701ce8584aa6ac4607c02e23bdfdf4b4dbca3ad1bc1600e0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.