OESA-2026-3121

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-3121
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-3121.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-3121
Upstream
  • CVE-2026-42012
Published
2026-07-24T03:26:32Z
Modified
2026-07-24T03:45:19.710686523Z
Summary
gnutls security update
Details

GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, and other required structures. The project strives to provide a secure communications back-end, simple to use and integrated with the rest of the base Linux libraries. A back-end designed to work and be secure out of the box, keeping the complexity of TLS and PKI out of application code.

Security Fix(es):

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.(CVE-2026-3832)

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.(CVE-2026-42012)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:24.03-LTS-SP3 / gnutls

Package

Name
gnutls
Purl
pkg:rpm/openEuler/gnutls&distro=openEuler-24.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.8.2-16.oe2403sp3

Ecosystem specific

{
    "x86_64": [
        "gnutls-3.8.2-16.oe2403sp3.x86_64.rpm",
        "gnutls-dane-3.8.2-16.oe2403sp3.x86_64.rpm",
        "gnutls-debuginfo-3.8.2-16.oe2403sp3.x86_64.rpm",
        "gnutls-debugsource-3.8.2-16.oe2403sp3.x86_64.rpm",
        "gnutls-devel-3.8.2-16.oe2403sp3.x86_64.rpm",
        "gnutls-utils-3.8.2-16.oe2403sp3.x86_64.rpm"
    ],
    "src": [
        "gnutls-3.8.2-16.oe2403sp3.src.rpm"
    ],
    "noarch": [
        "gnutls-help-3.8.2-16.oe2403sp3.noarch.rpm"
    ],
    "aarch64": [
        "gnutls-3.8.2-16.oe2403sp3.aarch64.rpm",
        "gnutls-dane-3.8.2-16.oe2403sp3.aarch64.rpm",
        "gnutls-debuginfo-3.8.2-16.oe2403sp3.aarch64.rpm",
        "gnutls-debugsource-3.8.2-16.oe2403sp3.aarch64.rpm",
        "gnutls-devel-3.8.2-16.oe2403sp3.aarch64.rpm",
        "gnutls-utils-3.8.2-16.oe2403sp3.aarch64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3121.json"