<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T12:04:04.098705+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-09658</id>
    <title>bdu:2026-09658</title>
    <updated>2026-10-02T12:04:04.158635+00:00</updated>
    <content>bdu:2026-09658</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-09658"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-42014</id>
    <title>BELL-CVE-2026-42014</title>
    <updated>2026-10-02T12:04:04.158689+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: gnutls, Alpaquita:25: gnutls, Alpaquita:stream: gnutls</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-42014"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-382049</id>
    <title>EUVD-2026-382049</title>
    <updated>2026-10-02T12:04:04.158723+00:00</updated>
    <content>EUVD-2026-382049</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-382049"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42014</id>
    <title>fkie_cve-2026-42014</title>
    <updated>2026-10-02T12:04:04.158736+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42014"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m4m5-7xc2-xc7g</id>
    <title>GHSA-m4m5-7xc2-xc7g</title>
    <updated>2026-10-02T12:04:04.158760+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m4m5-7xc2-xc7g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-42014</id>
    <title>msrc_CVE-2026-42014 — Gnutls: fix use-after-free in gnutls_pkcs11_token_set_pin</title>
    <updated>2026-10-02T12:04:04.158775+00:00</updated>
    <content>msrc_CVE-2026-42014</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-42014"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2333</id>
    <title>OESA-2026-2333 — gnutls security update</title>
    <updated>2026-10-02T12:04:04.158793+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: gnutls</p>
<p>GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, and other required structures. The project strives to provide a secure communications back-end, simple to use and integrated with the rest of the base Linux libraries. A back-end designed to work and be secure out of the box, keeping the complexity of TLS and PKI out of application code.

Security Fix(es):</p>
<p>A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application cra…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2333"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10691-1</id>
    <title>openSUSE-SU-2026:10691-1 — gnutls-3.8.13-1.1 on GA media</title>
    <updated>2026-10-02T12:04:04.158834+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>gnutls-3.8.13-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10691-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:13274</id>
    <title>RHSA-2026:13274 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T12:04:04.158858+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>gnutls: gnutls: Security bypass allows acceptance of revoked server certificates via crafted OCSP response gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison gnutls: gnutls: Information disclosure via heap overread in RSA key exchange gnutls: gnutls: Information disclosure via timing side-channel in PKCS#7 padding removal gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability gnutls: gnutls: Authentication Bypass via NUL Character in Username gnutls: gnutls: Security bypass due to incorrect name constraint handling gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name gnutls: gnutls: Use-after-free in gnutls_pkcs11_token_set_pin gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:13274"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:20612</id>
    <title>RLSA-2026:20612 — Important: gnutls security update</title>
    <updated>2026-10-02T12:04:04.158896+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: gnutls</p>
<p>The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library,
which implements cryptographic algorithms and protocols such as SSL, TLS, and
DTLS.</p>
<p>Security Fix(es):</p>
<p>* gnutls: Fix qsort comparator in DTLS reassembly (CVE-2026-42009)
* gnutls: Fix crashing on an underflow with a DTLS datagram
(CVE-2026-33845)
* gnutls: Fix RSA-PSK identity truncation (CVE-2026-42010)
* gnutls: Fix case-sensitivity of domain name comparison in name
constraints (CVE-2026-3833)
* gnutls: Fix intersecting empty name constraints (CVE-2026-42011)
* gnutls: Denial of Service via heap buffer overflow in DTLS handshake
fragment reassembly (CVE-2026-33846)</p>
<p>For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:20612"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:21752-1</id>
    <title>SUSE-SU-2026:21752-1 — Security update for gnutls</title>
    <updated>2026-10-02T12:04:04.158922+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for gnutls</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:21752-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42014</id>
    <title>UBUNTU-CVE-2026-42014</title>
    <updated>2026-10-02T12:04:04.158941+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:20.04:LTS: gnutls28, Ubuntu:22.04:LTS: gnutls28, Ubuntu:Pro:FIPS-preview:22.04:LTS: gnutls28, Ubuntu:Pro:FIPS-updates:22.04:LTS: gnutls28, Ubuntu:24.04:LTS: gnutls28, Ubuntu:Pro:FIPS-updates:24.04:LTS: gnutls28, Ubuntu:25.10: gnutls28, Ubuntu:26.04:LTS: gnutls28</p>
<p>A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42014"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1312</id>
    <title>WID-SEC-W-2026-1312 — GnuTLS: Mehrere Schwachstellen</title>
    <updated>2026-10-02T12:04:04.158973+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in GnuTLS ausnutzen, um Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1312"/>
  </entry>
</feed>
