CVE-2026-3832

Red Hat Security Advisory: Red Hat Update Infrastructure 5.3 Technology Preview security update

Beschreibung

Ein Fehler wurde in gnutls gefunden. Ein Fernangreifer könnte diese Schwachstelle ausnutzen, indem er während eines TLS-Handshakes eine speziell erstellte Antwort des Online Certificate Status Protocol (OCSP) präsentiert. Aufgrund eines Logikfehlers bei der Verarbeitung von mehrteiligen OCSP-Antworten durch gnutls könnte ein Client mit aktivierter OCSP-Überprüfung fälschlicherweise ein widerrufenes Serverzertifikat akzeptieren, was potenziell zu einem Vertrauensverlust führen kann.

Metriken

Severity
low
kein öffentlicher PoC bekannt
3.7
Quelle: nvd-v3
52.5 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.7 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-24 11:15 UTC
CWE-179

Weakness-Klassen (CWE)

  • CWE-179Base

    Incorrect Behavior Order: Early Validation

    The product validates input before applying protection mechanisms that modify the input, which could allow an attacker to bypass the validation via dangerous inputs that only arise after the modification.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-09-01 13:19 UTC· secalert@redhat.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/3xxx/CVE-2026-3832.json">CVE-2026-3832</a>
  2. CVE Modified2026-08-31 16:17 UTC· secalert@redhat.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/3xxx/CVE-2026-3832.json">CVE-2026-3832</a>
    • Reference: https://access.redhat.com/errata/RHSA-2026:13274
    • Reference: https://access.redhat.com/errata/RHSA-2026:20612
    • Reference: https://access.redhat.com/errata/RHSA-2026:20613
  3. CVE Modified2026-08-31 16:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • Reference: https://gitlab.com/gnutls/gnutls/-/issues/1801
    • Reference: https://gitlab.com/gnutls/gnutls/-/issues/1801
    • Reference Type: https://gitlab.com/gnutls/gnutls/-/issues/1801 Types: Exploit, Issue Tracking, Vendor Advisory
  4. CVE Modified2026-08-21 13:17 UTC· secalert@redhat.com
    • Affected: …, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support (+14)…, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support (+14)
  5. CVE Modified2026-06-24 17:16 UTC· secalert@redhat.com
    • Reference: https://access.redhat.com/errata/RHSA-2026:29197
    • Affected: …, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support (+11)…, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support (+13)

Betroffene Betriebssysteme

  • linux

    ubuntu / coreutilsjammy

  • linux

    ubuntu / coreutilsnoble

  • linux

    ubuntu / coreutilsresolute

  • linux

    debian / debian_linux11.0

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux10.2

  • linux

    redhat / enterprise_linux6.0

  • linux

    redhat / enterprise_linux7.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    redhat / enterprise_linux9.8

  • linux

    redhat / enterprise_linux_for_els10.2

  • linux

    redhat / enterprise_linux_for_els8.10

  • linux

    redhat / enterprise_linux_for_els9.8

  • linux

    redhat / enterprise_linux_for_eus10.2

  • linux

    redhat / enterprise_linux_for_eus9.8

  • linux

    redhat / enterprise_linux_for_ibm_z_systems10.2

  • linux

    redhat / enterprise_linux_for_ibm_z_systems8.0_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems9.0_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_els10.2

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_els8.10

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_els9.8

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus10.2

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus9.8

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • Apple

    iOS18.7.10

  • Apple

    iOS26.6.1

  • Apple

    iPadOS18.7.10

  • Apple

    iPadOS26.6.1

  • Apple

    macOSTahoe 26.6.2

  • bitnami

    jre1.9.0

  • bitnami

    nginx-gateway0.1.17

  • bitnami

    nginx-gateway-fabric1.3.0

  • bitnami

    postgresql15.0.0

  • bitnami

    postgresql16.0.0

  • bitnami

    postgresql17.0.0

  • bitnami

    postgresql18.0.0

  • bitnami

    python-min3.10.0

  • bitnami

    python-min3.11.0

  • bitnami

    python-min3.12.0

  • bitnami

    python-min3.13.0

  • bitnami

    python-min3.14.0

  • f5

    dos4.3.0 – 4.7.0

  • f5

    dos

  • f5

    nginx_gateway_fabric1.3.0 – 1.6.2

  • f5

    nginx_gateway_fabric2.0.0 – 2.5.1

  • f5

    nginx_ingress_controller3.5.0 – 3.7.2

  • f5

    nginx_ingress_controller4.0.0 – 4.0.1

  • f5

    nginx_ingress_controller5.0.0 – 5.4.1

Quellen & Referenzen

Verknüpfte CVEs

93 weitere CVEs anzeigen
IDCVE-2026-3832