Ubuntu alert USN-8502-1 (gnutls28)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8502-1] GnuTLS vulnerabilities | |
| Date: | Mon, 06 Jul 2026 15:42:22 +0000 | |
| Message-ID: | <E1wglSg-0004TB-N1@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8502-1 July 06, 2026 gnutls28 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in GnuTLS. Software Description: - gnutls28: GNU TLS library Details: It was discovered that GnuTLS had a timing side-channel when processing malformed ciphertexts in RSA-PSK ClientKeyExchange. A remote attacker could possibly use this issue to recover sensitive information. This issue only affected Ubuntu 18.04 LTS. (CVE-2024-0553) Bing Shi discovered that GnuTLS incorrectly handled decoding certain DER-encoded certificates. A remote attacker could possibly use this issue to cause GnuTLS to consume resources, leading to a denial of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2024-12243) Luigino Camastra discovered that GnuTLS incorrectly handled certain PKCS11 token labels. A remote attacker could use this issue to cause GnuTLS to crash, resulting in a denial of service, or possibly execute arbitrary code. The default compiler options for affected releases should reduce the vulnerability to a denial of service. (CVE-2025-9820) Tim Scheckenbach discovered that GnuTLS incorrectly handled malicious certificates containing a large number of name constraints and subject alternative names. A remote attacker could possibly use this issue to cause GnuTLS to consume resources, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2025-14831) Oleh Konko and Joshua Rogers discovered that GnuTLS did not properly handle case-insensitive name constraints in certain cases. A remote attacker could possibly use this issue to bypass certificate validation, leading to a machine-in-the-middle attack. (CVE-2026-3833) Joshua Rogers discovered that GnuTLS did not properly handle very short premaster secrets in certain RSA key exchange cases with PKCS#11-backed server keys. A remote attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2026-5260) Joshua Rogers discovered that GnuTLS did not properly handle malformed DTLS handshake fragments in certain cases. A remote attacker could possibly use this issue to obtain sensitive information, or cause a denial of service. This issue only affected Ubuntu 20.04 LTS. (CVE-2026-33845) Haruto Kimura, Oscar Reparaz, and Zou Dikai discovered that GnuTLS did not properly validate DTLS handshake fragment lengths in certain cases. A remote attacker could possibly use this issue to cause GnuTLS to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-33846) Joshua Rogers discovered that GnuTLS did not properly order DTLS packets with duplicate sequence numbers in certain cases. A remote attacker could possibly use this issue to cause GnuTLS to crash, resulting in a denial of service. (CVE-2026-42009) Joshua Rogers discovered that GnuTLS did not properly handle usernames containing NUL characters in certain RSA-PSK configurations. A remote attacker could possibly use this issue to bypass authentication and gain unintended access to services. This issue only affected Ubuntu 20.04 LTS. (CVE-2026-42010) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS gnutls-bin 3.6.13-2ubuntu1.12+esm2 Available with Ubuntu Pro guile-gnutls 3.6.13-2ubuntu1.12+esm2 Available with Ubuntu Pro libgnutls-dane0 3.6.13-2ubuntu1.12+esm2 Available with Ubuntu Pro libgnutls-openssl27 3.6.13-2ubuntu1.12+esm2 Available with Ubuntu Pro libgnutls28-dev 3.6.13-2ubuntu1.12+esm2 Available with Ubuntu Pro libgnutls30 3.6.13-2ubuntu1.12+esm2 Available with Ubuntu Pro libgnutlsxx28 3.6.13-2ubuntu1.12+esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS gnutls-bin 3.5.18-1ubuntu1.6+esm3 Available with Ubuntu Pro libgnutls-dane0 3.5.18-1ubuntu1.6+esm3 Available with Ubuntu Pro libgnutls-openssl27 3.5.18-1ubuntu1.6+esm3 Available with Ubuntu Pro libgnutls28-dev 3.5.18-1ubuntu1.6+esm3 Available with Ubuntu Pro libgnutls30 3.5.18-1ubuntu1.6+esm3 Available with Ubuntu Pro libgnutlsxx28 3.5.18-1ubuntu1.6+esm3 Available with Ubuntu Pro Ubuntu 16.04 LTS gnutls-bin 3.4.10-4ubuntu1.9+esm3 Available with Ubuntu Pro guile-gnutls 3.4.10-4ubuntu1.9+esm3 Available with Ubuntu Pro libgnutls-dev 3.4.10-4ubuntu1.9+esm3 Available with Ubuntu Pro libgnutls-openssl27 3.4.10-4ubuntu1.9+esm3 Available with Ubuntu Pro libgnutls28-dev 3.4.10-4ubuntu1.9+esm3 Available with Ubuntu Pro libgnutls30 3.4.10-4ubuntu1.9+esm3 Available with Ubuntu Pro libgnutlsxx28 3.4.10-4ubuntu1.9+esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8502-1 CVE-2024-0553, CVE-2024-12243, CVE-2025-14831, CVE-2025-9820, CVE-2026-33845, CVE-2026-33846, CVE-2026-3833, CVE-2026-42009, CVE-2026-42010, CVE-2026-5260
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmpLy5MACgkQcpJm3tlz hgEReRAAhlotjENOXOtfy7Uuu4rMuKxu1ZfapNMxrOzPWYLGYIkneh+5JQ67/4aW AS0AozjDtnYbiy0JbUvLkWD3nLdrxnD8+1bCFW8Es3cbhjwdptSJ5qK45miAbCDS XctTTKHDqHIm8fCPOLg/BvmsOYAQ55ZTp8UDrIVzBwBuq+yXzDub2/jgc53yUsvA yPLA/L4dOHkCKWa+1M5iiRngryuWu2iO7/hAo9ODOi2qauh6F+dces9U/sMIguiq NGq1SPNtcyVRLfGoyGsgKUOlzdGAMMSp0lYacZ6OAk/c6lQMMt0+YvGltBwyL66K uz/kPgVsL41WWx0wpMkaCr/bfAfWRJnJ4IDb+c0tFOoAdMkoFEGlDOozRayiyw/T bVnwRER4Qc9p1wMd4ensw0VtV5mJhDeWBQ+2Rt6ptCQjdQ5nkpq4vl4g+53nyfqG TmDBdXOxhqDyuTkfmKtkZk7E0zOUg4GNjYLu95U1MrREwxNLkLAiLhB26PM/NTk1 uw8yLpfY0ClpMlJ6a7LT69wx2KJg+myKKP3AG/i2r91OniwN5k5mbTdWj0K7nfGq 1dKlb+TeEKIi8sSDLYvFqtiJF2Yyh4qv0wwnnKTZV16WjM/nZY64+Uc35UioZyrO uYhY7Km3FvrApA63HcDGDZnpvpkNAhUyFnGe/NqmPQ9Q/NlYyS4= =3iLs -----END PGP SIGNATURE-----
