A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-04-30 18:16
Updated : 2026-09-04 13:19
NVD link : CVE-2026-33845
Mitre link : CVE-2026-33845
CVE.ORG link : CVE-2026-33845
JSON object : View
Products Affected
redhat
- enterprise_linux
- openshift_container_platform
gnu
- gnutls
CWE
CWE-191
Integer Underflow (Wrap or Wraparound)
