A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.
The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | RedHat | gnutls-0:3.8.10-4.el10_2 | * |
| Red Hat Enterprise Linux 10.0 Extended Update Support | RedHat | gnutls-0:3.8.9-9.el10_0.19 | * |
| Red Hat Enterprise Linux 8 | RedHat | gnutls-0:3.6.16-8.el8_10.6 | * |
| Red Hat Enterprise Linux 8 | RedHat | gnutls-0:3.6.16-8.el8_10.6 | * |
| Red Hat Enterprise Linux 9 | RedHat | gnutls-0:3.8.10-4.el9_8 | * |
| Red Hat Enterprise Linux 9 | RedHat | gnutls-0:3.8.10-4.el9_8 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/cds-rhel9:1781525684 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/haproxy-rhel9:1781525671 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/installer-rhel9:1781525693 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/rhua-rhel9:1781525739 | * |
| Gnutls28 | Ubuntu | devel | * |
| Gnutls28 | Ubuntu | esm-infra/xenial | * |
| Gnutls28 | Ubuntu | fips-preview/jammy | * |
| Gnutls28 | Ubuntu | fips-updates/jammy | * |
| Gnutls28 | Ubuntu | fips-updates/noble | * |
| Gnutls28 | Ubuntu | jammy | * |
| Gnutls28 | Ubuntu | noble | * |
| Gnutls28 | Ubuntu | questing | * |
| Gnutls28 | Ubuntu | resolute | * |
| Gnutls28 | Ubuntu | upstream | * |
Specified quantities include size, length, frequency, price, rate, number of operations, time, and others. Code may rely on specified quantities to allocate resources, perform calculations, control iteration, etc.