PT-2026-36149 · Gnu+4 · Gnutls+4

·

CVE-2026-33845

·

Published

2026-03-10

·

Updated

2026-09-03

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions GnuTLS (affected versions not specified)
Description A flaw in DTLS handshake parsing allows malformed fragments with zero length and non-zero offset to cause an integer underflow during reassembly. This leads to an out-of-bounds read, which is remotely exploitable and may result in information disclosure or denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Integer Underflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:20611
ALSA-2026:20612
ALSA-2026:20613
AZL-85983
BDU:2026-09340
CVE-2026-33845
ECHO-638C-85AD-8D98
OESA-2026-2221
OPENSUSE-SU-2026:10691-1
OPENSUSE-SU-2026:20778-1
RHSA-2026:13274
RHSA-2026:20611
RHSA-2026:20612
RHSA-2026:20613
RHSA-2026:26409
RHSA-2026:30004
RHSA-2026:32962
RHSA-2026:33125
RHSA-2026:34372
RHSA-2026:41921
SUSE-SU-2026:2087-1
SUSE-SU-2026:2115-1
SUSE-SU-2026:21752-1
SUSE-SU-2026:21784-1
SUSE-SU-2026:21815-1
SUSE-SU-2026:21867-1
SUSE-SU-2026:2366-1
SUSE-SU-2026:2367-1
SUSE-SU-2026:2822-1
USN-8284-1
USN-8502-1

Affected Products

Gnutls
Linuxmint
Red Os
Rocky Linux
Ubuntu