{"id":"AZL-89424","summary":"CVE-2026-5419 affecting package gnutls for versions less than 3.8.13-1","details":"A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.","modified":"2026-08-28T17:45:58.135353160Z","published":"2026-06-01T21:16:47Z","upstream":["CVE-2026-5419"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5419"}],"affected":[{"package":{"name":"gnutls","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/gnutls"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.8.13-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-89424.json"}}],"schema_version":"1.9.0"}