stable

gnutls-3.8.12-1.fc43

FEDORA-2026-ef7170c9f6 created by asosedkin 6 months ago for Fedora 43

This fixes a couple CVEs:

** libgnutls: Fix NULL pointer dereference in PSK binder verification A TLS 1.3 resumption attempt with an invalid PSK binder value in ClientHello could lead to a denial of service attack via crashing the server. The updated code guards against the problematic dereference. Reported by Jaehun Lee. [Fixes: GNUTLS-SA-2026-02-09-1, CVSS: high] [CVE-2026-1584]

** libgnutls: Fix name constraint processing performance issue Verifying certificates with pathological amounts of name constraints could lead to a denial of service attack via resource exhaustion. Reworked processing algorithms exhibit better performance characteristics. Reported by Tim Scheckenbach. [Fixes: GNUTLS-SA-2026-02-09-2, CVSS: medium] [CVE-2025-14831]

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2026-ef7170c9f6

This update has been submitted for testing by asosedkin.

6 months ago

This update's test gating status has been changed to 'waiting'.

6 months ago

This update's test gating status has been changed to 'waiting'.

6 months ago

This update's test gating status has been changed to 'passed'.

6 months ago

This update has been pushed to testing.

6 months ago
User Icon besser82 commented & provided feedback 6 months ago
karma

Works great! LGTM! =)

karma

This update can be pushed to stable now if the maintainer wishes

6 months ago

This update has been submitted for stable by asosedkin.

6 months ago
karma

This update has been pushed to stable.

6 months ago

Please log in to add feedback.

Metadata
Type
security
Karma
3
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
14 days
Dates
submitted
6 months ago
in testing
6 months ago
in stable
6 months ago
approved
6 months ago
BZ#2437987 CVE-2025-14831 gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification [fedora-43]
0
0
BZ#2437989 CVE-2026-1584 gnutls: gnutls: Remote Denial of Service via crafted ClientHello with invalid PSK binder [fedora-43]
0
0

Automated Test Results