CVE-2026-5260: Gnutls: gnutls: information disclosure via heap overread in rsa key exchange
A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.
Other sources
Gnutls: gnutls: information disclosure via heap overread in rsa key exchange
— Microsoft
libgnutls: Fix overread in RSA key exchange with PKCS#11 keys For a server using an RSA key backed by a PKCS#11 token, a client sending an extremely short premaster secret during an RSA key exchange could trigger a short heap overread.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.8.13-1 - Upgrade
Upgrade
debian/gnutls28to a version that resolves this vulnerability.Fixed in 3.7.1-5+deb11u10Fixed in 3.7.9-2+deb12u7Fixed in 3.8.9-3+deb13u4Fixed in 3.8.13-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5260?
The severity of CVE-2026-5260 is high with a score of 8.2.
How do I fix CVE-2026-5260?
To fix CVE-2026-5260, update to the latest version of libgnutls that addresses this vulnerability.
What type of attack does CVE-2026-5260 facilitate?
CVE-2026-5260 facilitates an information disclosure attack through a heap overread during RSA key exchange.
Which software is affected by CVE-2026-5260?
CVE-2026-5260 affects the debian/gnutls28 software package.
What could be the outcome of a successful exploit of CVE-2026-5260?
A successful exploit of CVE-2026-5260 could lead to the disclosure of sensitive information from the server.