CVE-2026-33845
published 2026-04-30CVE-2026-33845: A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and…
PriorityP351critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.80%
52.7th percentile
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | gnutls | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
| ubuntu | gnutls28 | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
vendor_ubuntu9.1CRITICAL
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cmj5-x3xf-69wq: A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reasse
ghsa_unreviewed·2026-04-30
CVE-2026-33845 [HIGH] CWE-191 GHSA-cmj5-x3xf-69wq: A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reasse
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.
VulDB
GnuTLS DTLS Handshake integer underflow
vuldb·2026-04-30·CVSS 7.5
CVE-2026-33845 [HIGH] GnuTLS DTLS Handshake integer underflow
A vulnerability was found in GnuTLS and classified as problematic. This impacts an unknown function of the component DTLS Handshake Handler. The manipulation results in integer underflow.
This vulnerability is identified as CVE-2026-33845. The attack can be executed remotely. There is not any exploit available.
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2026-07-06·CVSS 7.5
CVE-2026-33846 [HIGH] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
It was discovered that GnuTLS had a timing side-channel when processing
malformed ciphertexts in RSA-PSK ClientKeyExchange. A remote attacker
could possibly use this issue to recover sensitive information. This
issue only affected Ubuntu 18.04 LTS. (CVE-2024-0553)
Bing Shi discovered that GnuTLS incorrectly handled decoding certain
DER-encoded certificates. A remote attacker could possibly use this
issue to cause GnuTLS to consume resources, leading to a denial of
service. This issue only affected Ubuntu 18.04 LTS. (CVE-2024-12243)
Luigino Camastra discovered that GnuTLS incorrectly handled certain
PKCS11 token labels. A remote attacker could use this issue to cause
GnuTLS to crash, resulting in a deni
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2026-05-20·CVSS 9.1
CVE-2026-42015 [CRITICAL] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
Joshua Rogers discovered that GnuTLS did not properly handle malformed
DTLS handshake fragments in certain cases. A remote attacker could
possibly use this issue to obtain sensitive information, or cause a
denial of service. (CVE-2026-33845)
Haruto Kimura, Oscar Reparaz, and Zou Dikai discovered that GnuTLS did
not properly validate DTLS handshake fragment lengths in certain cases. A
remote attacker could possibly use this issue to cause GnuTLS to crash,
resulting in a denial of service, or execute arbitrary code.
(CVE-2026-33846)
Oleh Konko and Joshua Rogers discovered that GnuTLS did not properly
validate OCSP responses in certain cases. A remote attacker could
possibly use this issue to bypass certi
Red Hat
gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment
vendor_redhat·2026-04-30·CVSS 7.5
CVE-2026-33845 [HIGH] CWE-191 gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment
gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.
Statement: This issue marked as Important severity due to its remote, pre-authentication reachability and its impact on a critical DTLS handshake parsing path. The vulnerability can be triggered by an unauthenticated attacker sending crafted DTLS handshake fragments, requiring no prior access or interaction. It leads to an out-of-bounds read caused by an integer underflow in fragment reassembly, operating entirely on attacker-controlled inpu
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
blogs_hackernews·2026-05-18·CVSS 6.1
CVE-2026-42897 [MEDIUM] ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fake model page pushed a stealer. Then came the familiar ransom claim: the data was returned and deleted.
The pattern is clear. One weak dependency can leak keys. One leaked key can open cloud access. One cloud foothold can become a production incident. AI is speeding up vulnerability discovery, attackers are moving quickly, and old exposure still keeps paying off.
Patch the quiet risks first. Let’s g
Bugzilla
CVE-2026-33845 gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment [fedora-all]
bugzilla·2026-05-14·CVSS 9.1
CVE-2026-33845 [CRITICAL] CVE-2026-33845 gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment [fedora-all]
CVE-2026-33845 gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-33845 gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment
bugzilla·2026-03-24·CVSS 7.5
CVE-2026-33845 [HIGH] CVE-2026-33845 gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment
CVE-2026-33845 gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment
DTLS zero-length fragment for non-empty handshake can trigger out-of-bounds read
https://access.redhat.com/errata/RHSA-2026:13274https://access.redhat.com/errata/RHSA-2026:20611https://access.redhat.com/errata/RHSA-2026:20612https://access.redhat.com/errata/RHSA-2026:20613https://access.redhat.com/errata/RHSA-2026:26319https://access.redhat.com/errata/RHSA-2026:26409https://access.redhat.com/errata/RHSA-2026:29197https://access.redhat.com/errata/RHSA-2026:30004https://access.redhat.com/errata/RHSA-2026:30849https://access.redhat.com/errata/RHSA-2026:30850https://access.redhat.com/errata/RHSA-2026:32962https://access.redhat.com/errata/RHSA-2026:33125https://access.redhat.com/errata/RHSA-2026:34372https://access.redhat.com/errata/RHSA-2026:36004https://access.redhat.com/errata/RHSA-2026:36005https://access.redhat.com/errata/RHSA-2026:36006https://access.redhat.com/security/cve/CVE-2026-33845https://bugzilla.redhat.com/show_bug.cgi?id=2450624https://access.redhat.com/errata/RHSA-2026:13274https://access.redhat.com/errata/RHSA-2026:20611https://access.redhat.com/errata/RHSA-2026:20612https://access.redhat.com/errata/RHSA-2026:20613https://access.redhat.com/errata/RHSA-2026:26319https://access.redhat.com/errata/RHSA-2026:26409https://access.redhat.com/errata/RHSA-2026:29197https://access.redhat.com/errata/RHSA-2026:30004https://access.redhat.com/errata/RHSA-2026:30849https://access.redhat.com/errata/RHSA-2026:30850https://access.redhat.com/errata/RHSA-2026:32962https://access.redhat.com/errata/RHSA-2026:33125https://access.redhat.com/errata/RHSA-2026:34372https://access.redhat.com/errata/RHSA-2026:36004https://access.redhat.com/errata/RHSA-2026:36005https://access.redhat.com/errata/RHSA-2026:36006https://access.redhat.com/security/cve/CVE-2026-33845https://bugzilla.redhat.com/show_bug.cgi?id=2450624https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33845.json
2026-04-30
Published