OESA-2026-3118

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-3118
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-3118.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-3118
Upstream
  • CVE-2026-42012
Published
2026-07-24T03:26:19Z
Modified
2026-07-24T03:45:11.684271547Z
Summary
gnutls security update
Details

GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, and other required structures. The project strives to provide a secure communications back-end, simple to use and integrated with the rest of the base Linux libraries. A back-end designed to work and be secure out of the box, keeping the complexity of TLS and PKI out of application code.

Security Fix(es):

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.(CVE-2026-3832)

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.(CVE-2026-42012)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP4 / gnutls

Package

Name
gnutls
Purl
pkg:rpm/openEuler/gnutls&distro=openEuler-20.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.6.14-24.oe2003sp4

Ecosystem specific

{
    "aarch64": [
        "gnutls-3.6.14-24.oe2003sp4.aarch64.rpm",
        "gnutls-debuginfo-3.6.14-24.oe2003sp4.aarch64.rpm",
        "gnutls-debugsource-3.6.14-24.oe2003sp4.aarch64.rpm",
        "gnutls-devel-3.6.14-24.oe2003sp4.aarch64.rpm",
        "gnutls-utils-3.6.14-24.oe2003sp4.aarch64.rpm"
    ],
    "x86_64": [
        "gnutls-3.6.14-24.oe2003sp4.x86_64.rpm",
        "gnutls-debuginfo-3.6.14-24.oe2003sp4.x86_64.rpm",
        "gnutls-debugsource-3.6.14-24.oe2003sp4.x86_64.rpm",
        "gnutls-devel-3.6.14-24.oe2003sp4.x86_64.rpm",
        "gnutls-utils-3.6.14-24.oe2003sp4.x86_64.rpm"
    ],
    "noarch": [
        "gnutls-help-3.6.14-24.oe2003sp4.noarch.rpm"
    ],
    "src": [
        "gnutls-3.6.14-24.oe2003sp4.src.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3118.json"