CVE-2026-5260
GnuTLS vulnerability analysis and mitigation

Overview

CVE-2026-5260 is a heap overread vulnerability in libgnutls (GnuTLS) that allows a remote unauthenticated attacker to trigger memory corruption by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token. The flaw was reported internally (Red Hat Bugzilla ID 2467450) and publicly disclosed on May 26, 2026. Affected software includes GnuTLS as shipped with Red Hat Enterprise Linux 8 and 9, Debian, Ubuntu, SUSE, openSUSE, and Amazon Linux 2023, among other distributions. It carries a CVSS v3.1 base score of 8.2 (High) (Github Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-1284 (Improper Validation of Specified Quantity in Input): libgnutls does not properly validate the length of the premaster secret received during an RSA key exchange when the server's RSA private key is stored in a PKCS#11 hardware token (Github Advisory). When a client sends an abnormally short (e.g., zero or near-zero length) premaster secret, the library reads beyond the allocated heap buffer — a short heap overread — during the decryption or processing step that involves the PKCS#11 token interface (Red Hat Bugzilla). Exploitation requires no authentication and no user interaction; the only precondition is that the target server must be configured to use an RSA key backed by a PKCS#11 token for TLS/SSL handshakes. No public proof-of-concept code has been identified at this time.

Impact

Successful exploitation can result in two primary consequences: disclosure of sensitive data from server heap memory (confidentiality impact rated Low by CVSS, but potentially including cryptographic material or session data depending on heap layout) and a potential service crash causing denial of service (availability impact rated High) (Github Advisory, Red Hat CVE). Integrity is not directly affected. The scope is limited to the vulnerable server process; lateral movement is not a direct consequence, though memory disclosure could theoretically expose credentials or keys that enable further compromise.

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of this report (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.186% (roughly the 46th percentile), indicating a low but non-negligible probability of exploitation in the near term (Github Advisory). No threat actor attribution has been reported. The attack vector is network-accessible with no privileges or user interaction required, lowering the barrier for exploitation once a working technique is developed.

Mitigation and workarounds

Vendor patches have been released across multiple distributions. Red Hat issued RHSA-2026:20611 (RHEL 8, gnutls-3.6.16-8.el8_10.6) and RHSA-2026:20612 (RHEL 9, gnutls-3.8.10-4.el9_8) on May 26, 2026 (Red Hat RHSA-2026:20611, Red Hat RHSA-2026:20612). Ubuntu (USN-8284-1), Debian (DLA-4595-1), SUSE (SUSE-SU-2026:2087-1, SUSE-SU-2026:2115-1), openSUSE, and Amazon Linux 2023 (ALAS2023-2026-1757) have also released updated gnutls packages. As an interim workaround where patching is not immediately possible, administrators should implement network-level access controls to restrict RSA key exchange connections to trusted clients only, and consider disabling PKCS#11-backed RSA keys if operationally feasible (Github Advisory).

Community reactions

Red Hat assigned this vulnerability a medium severity rating internally despite the CVSS 8.2 High score, reflecting the constrained exploitation conditions (PKCS#11-backed RSA keys required) (Red Hat Bugzilla). The vulnerability was disclosed via the oss-security mailing list and has been picked up by Linux security news aggregators including LinuxSecurity.com and LinuxCompatible.org. No notable independent researcher commentary or significant social media discussion beyond routine CVE tracking has been observed.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

gnutls28: 3.7.9-2+deb12u7

Fixed

sid

gnutls28: 3.8.13-1

Fixed

trixie

gnutls28: 3.8.9-3+deb13u4

Fixed

Ubuntu

Fixed

bionic (esm-infra)

gnutls28: 3.5.18-1ubuntu1.6+esm3

Fixed

devel

gnutls28

Not Affected

focal (esm-infra)

gnutls28: 3.6.13-2ubuntu1.12+esm2

Fixed

jammy

gnutls28: 3.7.3-4ubuntu1.9

Fixed

jammy (fips-preview)

gnutls28

Affected

jammy (fips-updates)

gnutls28: 3.7.3-4ubuntu1.9+Fips1

Fixed

noble

gnutls28: 3.8.3-1.1ubuntu3.6

Fixed

noble (fips-updates)

gnutls28: 3.8.3-1.1ubuntu3.6+Fips1.2

Fixed

RHEL / CentOS

Fixed

OpenShift

el8:openshift/ose-rhel-coreos-8-0:412.86.202608241157-0

Fixed

RHEL 8

:appstream:gnutls-0:3.6.16-8.el8_10.6.src

Fixed

RHEL 9

:appstream:gnutls-0:3.7.6-21.el9_2.7.src

Fixed

RHEL 10

gnutls-0:3.8.9-9.el10_0.19.src

Fixed

Alpine

Fixed

edge

gnutls: 3.8.13-r0

Fixed

v3.20

gnutls: 3.8.13-r0

Fixed

v3.21

gnutls: 3.8.13-r0

Fixed

v3.22

gnutls: 3.8.13-r0

Fixed

v3.23

gnutls: 3.8.13-r0

Fixed

SourceThis report was generated using AI

Related GnuTLS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-5260HIGH8.2
  • GnuTLS logoGnuTLS
  • gnutls-debuginfo
NoYesMay 26, 2026
CVE-2026-42013HIGH8.2
  • GnuTLS logoGnuTLS
  • gnutls28
NoYesMay 26, 2026
CVE-2026-42014MEDIUM6.6
  • GnuTLS logoGnuTLS
  • libgnutls-devel-doc
NoYesJun 16, 2026
CVE-2026-42015MEDIUM5.3
  • GnuTLS logoGnuTLS
  • libgnutls30
NoYesMay 26, 2026
CVE-2026-5419LOW3.7
  • GnuTLS logoGnuTLS
  • gnutls-dane
NoYesJun 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management