Red Hat Security Advisory: Red Hat Update Infrastructure 5.2 security update
Red Hat Update Infrastructure (RHUI) container images are based on the latest RHUI RPM packages and the ubi9 or ubi9-init base images. This release updates to the latest version.
AI Analysis
Technical Summary
The gnutls library in Red Hat Enterprise Linux 10 contains multiple vulnerabilities, including a heap buffer overflow leading to denial of service during DTLS handshake fragment reassembly (CVE-2026-33846), a qsort comparator issue in DTLS reassembly (CVE-2026-42009), crashing on underflow with DTLS datagrams (CVE-2026-33845), RSA-PSK identity truncation causing authentication bypass (CVE-2026-42010), and incorrect handling of name constraints causing security bypass (CVE-2026-3833, CVE-2026-42011). These issues impact the cryptographic operations of GnuTLS, which implements SSL, TLS, and DTLS protocols. Red Hat has rated the update as having a moderate security impact and has issued patches in advisory RHSA-2026:20613 for Red Hat Enterprise Linux 10 across multiple architectures.
Potential Impact
The vulnerabilities could allow denial of service conditions via heap buffer overflow and DTLS packet reordering, authentication bypass through RSA-PSK identity truncation, and security bypass due to improper name constraint handling. Confidentiality impact is limited (low), with no integrity or availability impacts explicitly stated beyond denial of service. The issues affect the cryptographic protocol implementations, potentially undermining secure communications if exploited.
Mitigation Recommendations
Red Hat has released an official security update for gnutls in Red Hat Enterprise Linux 10 addressing these vulnerabilities. Users should apply the update as per Red Hat advisory RHSA-2026:20613 after ensuring all previous errata are applied. Detailed update instructions are available at https://access.redhat.com/articles/11258. No additional mitigations are indicated beyond applying the official patch.
Red Hat Security Advisory: Red Hat Update Infrastructure 5.2 security update
Description
Red Hat Update Infrastructure (RHUI) container images are based on the latest RHUI RPM packages and the ubi9 or ubi9-init base images. This release updates to the latest version.
CVSS v3.1
Score 3.7low
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The gnutls library in Red Hat Enterprise Linux 10 contains multiple vulnerabilities, including a heap buffer overflow leading to denial of service during DTLS handshake fragment reassembly (CVE-2026-33846), a qsort comparator issue in DTLS reassembly (CVE-2026-42009), crashing on underflow with DTLS datagrams (CVE-2026-33845), RSA-PSK identity truncation causing authentication bypass (CVE-2026-42010), and incorrect handling of name constraints causing security bypass (CVE-2026-3833, CVE-2026-42011). These issues impact the cryptographic operations of GnuTLS, which implements SSL, TLS, and DTLS protocols. Red Hat has rated the update as having a moderate security impact and has issued patches in advisory RHSA-2026:20613 for Red Hat Enterprise Linux 10 across multiple architectures.
Potential Impact
The vulnerabilities could allow denial of service conditions via heap buffer overflow and DTLS packet reordering, authentication bypass through RSA-PSK identity truncation, and security bypass due to improper name constraint handling. Confidentiality impact is limited (low), with no integrity or availability impacts explicitly stated beyond denial of service. The issues affect the cryptographic protocol implementations, potentially undermining secure communications if exploited.
Mitigation Recommendations
Red Hat has released an official security update for gnutls in Red Hat Enterprise Linux 10 addressing these vulnerabilities. Users should apply the update as per Red Hat advisory RHSA-2026:20613 after ensuring all previous errata are applied. Detailed update instructions are available at https://access.redhat.com/articles/11258. No additional mitigations are indicated beyond applying the official patch.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:20613
- Cve Count
- 13
- Additional Cves
- ["CVE-2026-3833","CVE-2026-5260","CVE-2026-5419","CVE-2026-33845","CVE-2026-33846","CVE-2026-42009","CVE-2026-42010","CVE-2026-42011","CVE-2026-42012","CVE-2026-42013","CVE-2026-42014","CVE-2026-42015"]
- Cvss Version
- 3.1
Threat ID: 6a1df65ee29bf47b5045f308
Added to database: 06/01/2026, 21:15:10 UTC
Last enriched: 07/23/2026, 00:51:24 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 199
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.