SUSE-SU-2026:2822-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20262822-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2822-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:2822-1
Upstream
  • CVE-2025-14831
  • CVE-2026-33846
  • CVE-2026-42009
  • CVE-2026-42010
  • CVE-2026-42011
  • CVE-2026-42012
  • CVE-2026-42013
  • CVE-2026-42014
  • CVE-2026-42015
  • CVE-2026-5260
Related
  • CVE-2025-14831
  • CVE-2026-33845
  • CVE-2026-33846
  • CVE-2026-3833
  • CVE-2026-42009
  • CVE-2026-42010
  • CVE-2026-42011
  • CVE-2026-42012
  • CVE-2026-42013
  • CVE-2026-42014
  • CVE-2026-42015
  • CVE-2026-5260
Published
2026-07-09T18:07:12Z
Modified
2026-07-10T10:00:08Z
Summary
Security update for gnutls
Details

This update for gnutls fixes the following issues

  • CVE-2025-14831: excessive resource consumption when verifying specially crafted malicious certificates containing a large number of name constraints and SANs (bsc#1257960).
  • CVE-2026-3833: incorrectly accepted domain names due to comparison during name constraints processing being case-sensitive (bsc#1263707).
  • CVE-2026-5260: heap overread when processing extremely short premaster secret as part of an RSA key exchange (bsc#1263715).
  • CVE-2026-33845: integer overflow and heap overrun when parsing fragments with zero length and non-zero offset during DTLS handshake (bsc#1263704).
  • CVE-2026-33846: heap overwrite during DTLS handshake fragment reassembly due to missing validations and checks (bsc#1263705).
  • CVE-2026-42009: undefined behavior resulting in a DoS when handling DTLS packets with duplicate sequence numbers (bsc#1263708).
  • CVE-2026-42010: authentication bypass when processing a PSK username with a NUL-character (bsc#1263709).
  • CVE-2026-42011: name constraint bypass leading to acceptance of invalid certificates during certificate validation (bsc#1263710).
  • CVE-2026-42012: spoofing of legitimate services and sensitive information interception via specially crafted certificates containing URIs or SRV SANs. (bsc#1263711).
  • CVE-2026-42013: certificate validation bypass when validating certificates with an oversized SAN (bsc#1263712).
  • CVE-2026-42014: use-after-free when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path (bsc#1263713).
  • CVE-2026-42015: memory corruption when appending to a PKCS#12 bag that already contains 32 elements (bsc#1263714).
References

Affected packages

SUSE:Linux Enterprise Micro 5.3 / gnutls

Package

Name
gnutls
Purl
pkg:rpm/suse/gnutls&distro=SUSE%20Linux%20Enterprise%20Micro%205.3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.7.3-150400.24.2

Ecosystem specific

{
    "binaries":  [
        {
            "gnutls":  "3.7.3-150400.24.2",
            "libgnutls30":  "3.7.3-150400.24.2",
            "libgnutls30-hmac":  "3.7.3-150400.24.2"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2822-1.json"