RHSA-2026:34372: Important: gnutls security update
Important: gnutls security update
Other sources
The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS.Security Fix(es): gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment (CVE-2026-33845) gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly (CVE-2026-33846) gnutls: Fix qsort comparator in DTLS reassembly (CVE-2026-42009) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/gnutlsto a version that resolves this vulnerability.Fixed in 3.3.29-9.el7_9.1 - Upgrade
Upgrade
redhat/gnutls-daneto a version that resolves this vulnerability.Fixed in 3.3.29-9.el7_9.1 - Upgrade
Upgrade
redhat/gnutls-debuginfoto a version that resolves this vulnerability.Fixed in 3.3.29-9.el7_9.1 - Upgrade
Upgrade
redhat/gnutls-develto a version that resolves this vulnerability.Fixed in 3.3.29-9.el7_9.1 - Upgrade
Upgrade
redhat/gnutls-utilsto a version that resolves this vulnerability.Fixed in 3.3.29-9.el7_9.1
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:34372?
The severity of RHSA-2026:34372 is high with a score of 7.
What security issues does RHSA-2026:34372 address?
RHSA-2026:34372 addresses a denial of service vulnerability via DTLS zero-length fragment, identified as CVE-2026-33845.
How do I fix RHSA-2026:34372?
To fix RHSA-2026:34372, update the gnutls packages to the latest version provided by Red Hat.
Which software packages are affected by RHSA-2026:34372?
The affected software packages include redhat/gnutls, redhat/gnutls-dane, redhat/gnutls-debuginfo, redhat/gnutls-devel, and redhat/gnutls-utils.
What platforms are impacted by RHSA-2026:34372?
RHSA-2026:34372 impacts Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, both big and little endian.