CVE-2026-33845: Gnutls: gnutls: denial of service via dtls zero-length fragment
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.
Other sources
DTLS zero-length fragment for non-empty handshake can trigger out-of-bounds read
— Red Hat
Gnutls: gnutls: denial of service via dtls zero-length fragment
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/gnutls28to a version that resolves this vulnerability.Fixed in 3.7.1-5+deb11u10Fixed in 3.7.9-2+deb12u7Fixed in 3.8.9-3+deb13u4Fixed in 3.8.13-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33845?
CVE-2026-33845 is classified as a denial of service vulnerability that can be exploited remotely.
How do I fix CVE-2026-33845?
To fix CVE-2026-33845, update GnuTLS and affected systems to the latest patched versions provided by the vendor.
Who is affected by CVE-2026-33845?
CVE-2026-33845 affects users of GnuTLS and several versions of Red Hat Enterprise Linux and OpenShift Container Platform.
What happens if CVE-2026-33845 is exploited?
Exploitation of CVE-2026-33845 can lead to an integer underflow and an out-of-bounds read, resulting in a denial of service.
Is CVE-2026-33845 remotely exploitable?
Yes, CVE-2026-33845 is remotely exploitable through malformed DTLS fragments.