{"id":"OESA-2026-3118","summary":"gnutls security update","details":"GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, and other required structures. The project strives to provide a secure communications back-end, simple to use and integrated with the rest of the base Linux libraries. A back-end designed to work and be secure out of the box, keeping the complexity of TLS and PKI out of application code.\r\n\r\nSecurity Fix(es):\n\nA flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.(CVE-2026-3832)\n\nA flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.(CVE-2026-42012)","modified":"2026-07-24T03:45:11.684271547Z","published":"2026-07-24T03:26:19Z","upstream":["CVE-2026-3832","CVE-2026-42012"],"database_specific":{"severity":"High"},"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3118"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-3832"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42012"}],"affected":[{"package":{"name":"gnutls","ecosystem":"openEuler:20.03-LTS-SP4","purl":"pkg:rpm/openEuler/gnutls&distro=openEuler-20.03-LTS-SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.14-24.oe2003sp4"}]}],"ecosystem_specific":{"noarch":["gnutls-help-3.6.14-24.oe2003sp4.noarch.rpm"],"src":["gnutls-3.6.14-24.oe2003sp4.src.rpm"],"x86_64":["gnutls-3.6.14-24.oe2003sp4.x86_64.rpm","gnutls-debuginfo-3.6.14-24.oe2003sp4.x86_64.rpm","gnutls-debugsource-3.6.14-24.oe2003sp4.x86_64.rpm","gnutls-devel-3.6.14-24.oe2003sp4.x86_64.rpm","gnutls-utils-3.6.14-24.oe2003sp4.x86_64.rpm"],"aarch64":["gnutls-3.6.14-24.oe2003sp4.aarch64.rpm","gnutls-debuginfo-3.6.14-24.oe2003sp4.aarch64.rpm","gnutls-debugsource-3.6.14-24.oe2003sp4.aarch64.rpm","gnutls-devel-3.6.14-24.oe2003sp4.aarch64.rpm","gnutls-utils-3.6.14-24.oe2003sp4.aarch64.rpm"]},"database_specific":{"source":"https://repo.openeuler.org/security/data/osv/OESA-2026-3118.json"}}],"schema_version":"1.7.5"}