Zurück zur CVE-Übersicht
CVE-2026-5419
LOW(3.7)CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Risk Signal Score9/100 — NIEDRIG
EPSS-Score
0%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
3.7
Technische Schwere
Beschreibung
A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.
Referenzen
- https://access.redhat.com/errata/RHSA-2026:20612
- https://access.redhat.com/errata/RHSA-2026:20613
- https://access.redhat.com/errata/RHSA-2026:26319
- https://access.redhat.com/errata/RHSA-2026:26409
- https://access.redhat.com/errata/RHSA-2026:29197
- https://access.redhat.com/errata/RHSA-2026:30004
- https://access.redhat.com/errata/RHSA-2026:32962
- https://access.redhat.com/security/cve/CVE-2026-5419
- https://bugzilla.redhat.com/show_bug.cgi?id=2467686
- https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-13