
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5260 is a heap overread vulnerability in libgnutls (GnuTLS) that allows a remote unauthenticated attacker to trigger memory corruption by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token. The flaw was reported internally (Red Hat Bugzilla ID 2467450) and publicly disclosed on May 26, 2026. Affected software includes GnuTLS as shipped with Red Hat Enterprise Linux 8 and 9, Debian, Ubuntu, SUSE, openSUSE, and Amazon Linux 2023, among other distributions. It carries a CVSS v3.1 base score of 8.2 (High) (Github Advisory, Red Hat CVE).
The root cause is classified as CWE-1284 (Improper Validation of Specified Quantity in Input): libgnutls does not properly validate the length of the premaster secret received during an RSA key exchange when the server's RSA private key is stored in a PKCS#11 hardware token (Github Advisory). When a client sends an abnormally short (e.g., zero or near-zero length) premaster secret, the library reads beyond the allocated heap buffer — a short heap overread — during the decryption or processing step that involves the PKCS#11 token interface (Red Hat Bugzilla). Exploitation requires no authentication and no user interaction; the only precondition is that the target server must be configured to use an RSA key backed by a PKCS#11 token for TLS/SSL handshakes. No public proof-of-concept code has been identified at this time.
Successful exploitation can result in two primary consequences: disclosure of sensitive data from server heap memory (confidentiality impact rated Low by CVSS, but potentially including cryptographic material or session data depending on heap layout) and a potential service crash causing denial of service (availability impact rated High) (Github Advisory, Red Hat CVE). Integrity is not directly affected. The scope is limited to the vulnerable server process; lateral movement is not a direct consequence, though memory disclosure could theoretically expose credentials or keys that enable further compromise.
Vendor patches have been released across multiple distributions. Red Hat issued RHSA-2026:20611 (RHEL 8, gnutls-3.6.16-8.el8_10.6) and RHSA-2026:20612 (RHEL 9, gnutls-3.8.10-4.el9_8) on May 26, 2026 (Red Hat RHSA-2026:20611, Red Hat RHSA-2026:20612). Ubuntu (USN-8284-1), Debian (DLA-4595-1), SUSE (SUSE-SU-2026:2087-1, SUSE-SU-2026:2115-1), openSUSE, and Amazon Linux 2023 (ALAS2023-2026-1757) have also released updated gnutls packages. As an interim workaround where patching is not immediately possible, administrators should implement network-level access controls to restrict RSA key exchange connections to trusted clients only, and consider disabling PKCS#11-backed RSA keys if operationally feasible (Github Advisory).
Red Hat assigned this vulnerability a medium severity rating internally despite the CVSS 8.2 High score, reflecting the constrained exploitation conditions (PKCS#11-backed RSA keys required) (Red Hat Bugzilla). The vulnerability was disclosed via the oss-security mailing list and has been picked up by Linux security news aggregators including LinuxSecurity.com and LinuxCompatible.org. No notable independent researcher commentary or significant social media discussion beyond routine CVE tracking has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."