CVE-2024-0567
published 2024-01-16CVE-2024-0567: A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.41%
69.6th percentile
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | gnutls28 | < gnutls28 3.7.9-2+deb12u2 (bookworm) | gnutls28 3.7.9-2+deb12u2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | gnutls | >= 3.7.0 < 3.8.3 | 3.8.3 |
| msrc | azl3_gnutls_3.8.2-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_gnutls_3.8.3-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_gnutls_3.7.11-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2024-01-22·CVSS 7.5
CVE-2024-0553 [HIGH] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
It was discovered that GnuTLS had a timing side-channel when processing
malformed ciphertexts in RSA-PSK ClientKeyExchange. A remote attacker could
possibly use this issue to recover sensitive information. (CVE-2024-0553)
It was discovered that GnuTLS incorrectly handled certain certificate
chains with a cross-signing loop. A remote attacker could possibly use this
issue to cause GnuTLS to crash, resulting in a denial of service. This
issue only affected Ubuntu 22.04 LTS, Ubuntu 23.04, and Ubuntu 23.10.
(CVE-2024-0567)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gnutls: rejects certificate chain with distributed trust
vendor_redhat·2024-01-16·CVSS 7.5
CVE-2024-0567 [HIGH] CWE-347 gnutls: rejects certificate chain with distributed trust
gnutls: rejects certificate chain with distributed trust
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.
Statement: The issue is marked as moderate because it involves a vulnerability in GnuTLS, specifically affecti
Microsoft
Gnutls: rejects certificate chain with distributed trust
vendor_msrc·2024-01-09·CVSS 7.5
CVE-2024-0567 [HIGH] CWE-347 Gnutls: rejects certificate chain with distributed trust
Gnutls: rejects certificate chain with distributed trust
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://le
Debian
CVE-2024-0567: gnutls28 - A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects...
vendor_debian·2024·CVSS 7.5
CVE-2024-0567 [HIGH] CVE-2024-0567: gnutls28 - A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects...
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.
Scope: local
bookworm: resolved (fixed in 3.7.9-2+deb12u2)
bullseye: resolved (fixed in 3.7.1-5+deb11u5)
forky: resolved (fixed in 3.8.3-1)
sid: resolved (fixed in 3.8.3-1)
trixie: resolved (fixed in 3.8.3-1)
OSV
gnutls28 vulnerabilities
osv·2024-01-22·CVSS 7.5
CVE-2024-0553 [HIGH] gnutls28 vulnerabilities
gnutls28 vulnerabilities
It was discovered that GnuTLS had a timing side-channel when processing
malformed ciphertexts in RSA-PSK ClientKeyExchange. A remote attacker could
possibly use this issue to recover sensitive information. (CVE-2024-0553)
It was discovered that GnuTLS incorrectly handled certain certificate
chains with a cross-signing loop. A remote attacker could possibly use this
issue to cause GnuTLS to crash, resulting in a denial of service. This
issue only affected Ubuntu 22.04 LTS, Ubuntu 23.04, and Ubuntu 23.10.
(CVE-2024-0567)
GHSA
GHSA-mcx8-9rrj-7qxm: A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust
ghsa_unreviewed·2024-01-16
CVE-2024-0567 [MEDIUM] CWE-347 GHSA-mcx8-9rrj-7qxm: A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.
OSV
CVE-2024-0567: A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust
osv·2024-01-16·CVSS 7.5
CVE-2024-0567 [HIGH] CVE-2024-0567: A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2024-0567 gnutls: rejects certificate chain with distributed trust
bugzilla·2024-01-16·CVSS 7.5
CVE-2024-0567 [HIGH] CVE-2024-0567 gnutls: rejects certificate chain with distributed trust
CVE-2024-0567 gnutls: rejects certificate chain with distributed trust
Cockpit (which uses gnuTLS) rejects certificate chain with distributed trust.
https://gitlab.com/gnutls/gnutls/-/issues/1521
Discussion:
Created cockpit tracking bugs for this issue:
Affects: fedora-all [bug 2258575]
Created gnutls tracking bugs for this issue:
Affects: fedora-all [bug 2258576]
---
Sandipan, what do you want Cockpit to do about this? This was a bug in GnuTLS, and there's a fix. Applying it to Fedora's and RHEL's gnutls packages should suffice to close this issue.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:0533 https://access.redhat.com/errata/RHSA-2024:0533
---
This issue has been addressed in the following products:
Red Hat Ent
Trailofbits
Celebrating our 2024 open-source contributions
blogs_trailofbits·2025-01-23
Celebrating our 2024 open-source contributions
While Trail of Bits is known for developing security tools like Slither , Medusa , and Fickling , our engineering efforts extend far beyond our own projects. Throughout 2024, our team has been deeply engaged with the broader security ecosystem, tackling challenges in open-source tools and infrastructure that security engineers rely on every day.
This year, our engineers submitted over 750 pull requests that were successfully merged (a 67% increase over our 2023 contributions !) with improvements across more than 80 open-source projects, ranging from foundational cryptography libraries to package managers and software indexes. Each contribution is a response to real-world security engineering challenges—when we encounter limitations in critical tools, we dig in and improve them. When we di
Trailofbits
Celebrating our 2024 open-source contributions
blogs_trailofbits·2025-01-23
Celebrating our 2024 open-source contributions
While Trail of Bits is known for developing security tools like Slither, Medusa, and Fickling, our engineering efforts extend far beyond our own projects. Throughout 2024, our team has been deeply engaged with the broader security ecosystem, tackling challenges in open-source tools and infrastructure that security engineers rely on every day.
This year, our engineers submitted over 750 pull requests that were successfully merged (a 67% increase over our 2023 contributions!) with improvements across more than 80 open-source projects, ranging from foundational cryptography libraries to package managers and software indexes. Each contribution is a response to real-world security engineering challenges—when we encounter limitations in critical tools, we dig in and improve them. When we discov
https://access.redhat.com/errata/RHSA-2024:0533https://access.redhat.com/errata/RHSA-2024:1082https://access.redhat.com/errata/RHSA-2024:1383https://access.redhat.com/errata/RHSA-2024:2094https://access.redhat.com/security/cve/CVE-2024-0567https://bugzilla.redhat.com/show_bug.cgi?id=2258544https://gitlab.com/gnutls/gnutls/-/issues/1521https://lists.gnupg.org/pipermail/gnutls-help/2024-January/004841.htmlhttp://www.openwall.com/lists/oss-security/2024/01/19/3https://access.redhat.com/errata/RHSA-2024:0533https://access.redhat.com/errata/RHSA-2024:1082https://access.redhat.com/errata/RHSA-2024:1383https://access.redhat.com/errata/RHSA-2024:2094https://access.redhat.com/security/cve/CVE-2024-0567https://bugzilla.redhat.com/show_bug.cgi?id=2258544https://gitlab.com/gnutls/gnutls/-/issues/1521https://lists.fedoraproject.org/archives/list/[email protected]/message/7ZEIOLORQ7N6WRPFXZSYDL2MC4LP7VFV/https://lists.fedoraproject.org/archives/list/[email protected]/message/GNXKVR5YNUEBNHAHM5GSYKBZX4W2HMN2/https://lists.gnupg.org/pipermail/gnutls-help/2024-January/004841.htmlhttps://security.netapp.com/advisory/ntap-20240202-0011/
2024-01-16
Published