CVE-2026-42010: Improper Null Termination
CVE-2026-42010 is a vulnerability in GnuTLS affecting servers configured with RSA-PSK authentication. The flaw involves improper handling of usernames containing a null (NUL) character, causing the server to match truncated usernames incorrectly. This can be exploited remotely by sending a specially crafted username to bypass authentication and gain unauthorized access. The vulnerability has a CVSS score of 7.1, indicating high severity. Red Hat has released security updates addressing this issue in GnuTLS packages for various Red Hat products, including Red Hat Enterprise Linux 8 and Red Hat Hardened Images. Users are advised to apply these updates to mitigate the risk.
AI Analysis
Technical Summary
The vulnerability CVE-2026-42010 in GnuTLS arises from improper null termination handling in RSA-PSK username matching. Specifically, servers configured with RSA-PSK authentication incorrectly match usernames containing a NUL character with truncated usernames, enabling an attacker to bypass authentication by sending a crafted username. This flaw allows unauthorized access by circumventing the authentication process. Red Hat has issued security advisories and updates for affected GnuTLS packages, including versions >=4.22.0 and <4.22.4, and for Red Hat Enterprise Linux 8 packages such as gnutls-3.6.16-8.el8_10.6. The updates fix the authentication bypass and other related security issues. The CVSS v3.1 base score is 7.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N), reflecting a high severity impact primarily on confidentiality.
Potential Impact
An attacker can exploit this vulnerability to bypass authentication on servers using GnuTLS with RSA-PSK, gaining unauthorized access. The impact is high confidentiality loss with limited integrity impact and no availability impact. This can lead to unauthorized access to protected resources or services relying on GnuTLS authentication.
Mitigation Recommendations
Red Hat has released official security updates that fix this vulnerability. Users should apply the updated GnuTLS packages provided in Red Hat advisories RHSA-2026:13274 and RHSA-2026:20611. The updates include gnutls-3.8.13-1.hum1 for Red Hat Hardened Images and gnutls-3.6.16-8.el8_10.6 for Red Hat Enterprise Linux 8. Applying these updates mitigates the authentication bypass issue. No additional mitigation steps are required beyond applying the vendor-provided patches.
CVE-2026-42010: Improper Null Termination
Description
CVE-2026-42010 is a vulnerability in GnuTLS affecting servers configured with RSA-PSK authentication. The flaw involves improper handling of usernames containing a null (NUL) character, causing the server to match truncated usernames incorrectly. This can be exploited remotely by sending a specially crafted username to bypass authentication and gain unauthorized access. The vulnerability has a CVSS score of 7.1, indicating high severity. Red Hat has released security updates addressing this issue in GnuTLS packages for various Red Hat products, including Red Hat Enterprise Linux 8 and Red Hat Hardened Images. Users are advised to apply these updates to mitigate the risk.
CVSS v3.1
Score 7.1high
Affected software
pkg:rpm/redhat/openshift-container-platformRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-42010 in GnuTLS arises from improper null termination handling in RSA-PSK username matching. Specifically, servers configured with RSA-PSK authentication incorrectly match usernames containing a NUL character with truncated usernames, enabling an attacker to bypass authentication by sending a crafted username. This flaw allows unauthorized access by circumventing the authentication process. Red Hat has issued security advisories and updates for affected GnuTLS packages, including versions >=4.22.0 and <4.22.4, and for Red Hat Enterprise Linux 8 packages such as gnutls-3.6.16-8.el8_10.6. The updates fix the authentication bypass and other related security issues. The CVSS v3.1 base score is 7.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N), reflecting a high severity impact primarily on confidentiality.
Potential Impact
An attacker can exploit this vulnerability to bypass authentication on servers using GnuTLS with RSA-PSK, gaining unauthorized access. The impact is high confidentiality loss with limited integrity impact and no availability impact. This can lead to unauthorized access to protected resources or services relying on GnuTLS authentication.
Mitigation Recommendations
Red Hat has released official security updates that fix this vulnerability. Users should apply the updated GnuTLS packages provided in Red Hat advisories RHSA-2026:13274 and RHSA-2026:20611. The updates include gnutls-3.8.13-1.hum1 for Red Hat Hardened Images and gnutls-3.6.16-8.el8_10.6 for Red Hat Enterprise Linux 8. Applying these updates mitigates the authentication bypass issue. No additional mitigation steps are required beyond applying the vendor-provided patches.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:34790
- Cve Count
- 1
- State
- PUBLISHED
Threat ID: 6a55ffc368715ace432fccde
Added to database: 07/14/2026, 09:22:11 UTC
Last enriched: 09/12/2026, 15:02:54 UTC
Last updated: 09/15/2026, 00:23:06 UTC
Views: 159
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.