Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:3477 - Security Advisory
Issued:
2026-03-02
Updated:
2026-03-02

RHSA-2026:3477 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: gnutls security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for gnutls is now available for Red Hat Enterprise Linux 10.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS.

Security Fix(es):

  • gnutls: Stack-based Buffer Overflow in gnutls_pkcs11_token_init() Function (CVE-2025-9820)
  • gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification (CVE-2025-14831)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 10 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 10 s390x
  • Red Hat Enterprise Linux for Power, little endian 10 ppc64le
  • Red Hat Enterprise Linux for ARM 64 10 aarch64

Fixes

  • BZ - 2392528 - CVE-2025-9820 gnutls: Stack-based Buffer Overflow in gnutls_pkcs11_token_init() Function
  • BZ - 2423177 - CVE-2025-14831 gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification

CVEs

  • CVE-2025-9820
  • CVE-2025-14831

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 10

SRPM
gnutls-3.8.10-3.el10_1.src.rpm SHA-256: 0b3ceb3a84a45ac199e9e452f53c358ffa26fa9f881e006290c38cb468a2ea1a
x86_64
gnutls-3.8.10-3.el10_1.x86_64.rpm SHA-256: 7daaa6cc91e87dc3e1e45d814963f6bc97f23287ad06f79163bc23f793af1924
gnutls-c++-3.8.10-3.el10_1.x86_64.rpm SHA-256: 018a28dbf52c4afd6c255b2a3a6708f20431c65c24ee3b77d665d0fcf559317a
gnutls-c++-debuginfo-3.8.10-3.el10_1.x86_64.rpm SHA-256: 7ac4b9ae0f2140352df1f777010b21a34178486d11e17f9b71db212c2e0e16a1
gnutls-c++-debuginfo-3.8.10-3.el10_1.x86_64.rpm SHA-256: 7ac4b9ae0f2140352df1f777010b21a34178486d11e17f9b71db212c2e0e16a1
gnutls-dane-3.8.10-3.el10_1.x86_64.rpm SHA-256: 0bb3d8f45b6e2f7c4437339643447fcf08ebacfcfcfdf5d506d747056407ac32
gnutls-dane-debuginfo-3.8.10-3.el10_1.x86_64.rpm SHA-256: dfcc966c4ab4d5f4909d06210c7017de19d992647af8409302780200b8b8622f
gnutls-dane-debuginfo-3.8.10-3.el10_1.x86_64.rpm SHA-256: dfcc966c4ab4d5f4909d06210c7017de19d992647af8409302780200b8b8622f
gnutls-debuginfo-3.8.10-3.el10_1.x86_64.rpm SHA-256: aab747943a8e27d27a2399ee83267b140c199ed268f8d62fba5f692f3c1405e0
gnutls-debuginfo-3.8.10-3.el10_1.x86_64.rpm SHA-256: aab747943a8e27d27a2399ee83267b140c199ed268f8d62fba5f692f3c1405e0
gnutls-debugsource-3.8.10-3.el10_1.x86_64.rpm SHA-256: 35c28924b185d0a5d44df2b03990d270f3fc6bb7969056b68f9ea50ae4d97179
gnutls-debugsource-3.8.10-3.el10_1.x86_64.rpm SHA-256: 35c28924b185d0a5d44df2b03990d270f3fc6bb7969056b68f9ea50ae4d97179
gnutls-devel-3.8.10-3.el10_1.x86_64.rpm SHA-256: 0ae8a7202506b46dd01408196c044947055dcc81f56c91325679bbf7e6acc1a1
gnutls-fips-3.8.10-3.el10_1.x86_64.rpm SHA-256: 1137ce2eaa6089c0e3fa8e060e9bc25d7b3abe08ca150d106317a706ea8e4bb2
gnutls-utils-3.8.10-3.el10_1.x86_64.rpm SHA-256: 722019632ee0ec6b7fa759b2ec795e0d91a231b75aa0f33a1821ed9e57f8c7c3
gnutls-utils-debuginfo-3.8.10-3.el10_1.x86_64.rpm SHA-256: a1a590549ab6ccc53978ab9589b6b51c338a8b8ee1f96e235b03b62edd3c7daf
gnutls-utils-debuginfo-3.8.10-3.el10_1.x86_64.rpm SHA-256: a1a590549ab6ccc53978ab9589b6b51c338a8b8ee1f96e235b03b62edd3c7daf

Red Hat Enterprise Linux for IBM z Systems 10

SRPM
gnutls-3.8.10-3.el10_1.src.rpm SHA-256: 0b3ceb3a84a45ac199e9e452f53c358ffa26fa9f881e006290c38cb468a2ea1a
s390x
gnutls-3.8.10-3.el10_1.s390x.rpm SHA-256: c72716900e62d6cab282d6f69da6eaf056524ea66b4d6e2ae8439b397e8dca40
gnutls-c++-3.8.10-3.el10_1.s390x.rpm SHA-256: 3b4c8132bd444c0b021c85b88d8123ba57364ea30682a8a8df987c6f7035231c
gnutls-c++-debuginfo-3.8.10-3.el10_1.s390x.rpm SHA-256: 026ceeaeae5112c54331f11447d1fefddc2ade0243072b3f3e80c9d849e51bc1
gnutls-c++-debuginfo-3.8.10-3.el10_1.s390x.rpm SHA-256: 026ceeaeae5112c54331f11447d1fefddc2ade0243072b3f3e80c9d849e51bc1
gnutls-dane-3.8.10-3.el10_1.s390x.rpm SHA-256: bf664e59b515699882557a00887fc8764dc1827072522643f97f11d2b5b49309
gnutls-dane-debuginfo-3.8.10-3.el10_1.s390x.rpm SHA-256: 027a347cae08176d3166fa5940bf0878456f9ec93ff4c2ce8f6bf26154264888
gnutls-dane-debuginfo-3.8.10-3.el10_1.s390x.rpm SHA-256: 027a347cae08176d3166fa5940bf0878456f9ec93ff4c2ce8f6bf26154264888
gnutls-debuginfo-3.8.10-3.el10_1.s390x.rpm SHA-256: cec8509e2b2691f4ce1e93c0ad0ea88fb96c0671470ca4a63c3c6e16d64c0741
gnutls-debuginfo-3.8.10-3.el10_1.s390x.rpm SHA-256: cec8509e2b2691f4ce1e93c0ad0ea88fb96c0671470ca4a63c3c6e16d64c0741
gnutls-debugsource-3.8.10-3.el10_1.s390x.rpm SHA-256: bcf9dbe2eef862e37de9750cfe8b5081c23d7451ce32494954a35375ab2254ae
gnutls-debugsource-3.8.10-3.el10_1.s390x.rpm SHA-256: bcf9dbe2eef862e37de9750cfe8b5081c23d7451ce32494954a35375ab2254ae
gnutls-devel-3.8.10-3.el10_1.s390x.rpm SHA-256: 3cf0c1e1ad65623a6fc78e3e988ad5cb9ede0a18e0105c5d9a2198f81b2d790c
gnutls-fips-3.8.10-3.el10_1.s390x.rpm SHA-256: c287fbc55bd918f3304a2940812b1fb42a7a76b170a5de6c5291c24bd60b7ab6
gnutls-utils-3.8.10-3.el10_1.s390x.rpm SHA-256: 6c737e97fae0f71aa88e98aee983e9d26621c7715c13f6185e1cae19781849f3
gnutls-utils-debuginfo-3.8.10-3.el10_1.s390x.rpm SHA-256: 62ee13f20dd0c4ce24357ba22c3acfedbf3351ebe5692272c557ad5dada556fe
gnutls-utils-debuginfo-3.8.10-3.el10_1.s390x.rpm SHA-256: 62ee13f20dd0c4ce24357ba22c3acfedbf3351ebe5692272c557ad5dada556fe

Red Hat Enterprise Linux for Power, little endian 10

SRPM
gnutls-3.8.10-3.el10_1.src.rpm SHA-256: 0b3ceb3a84a45ac199e9e452f53c358ffa26fa9f881e006290c38cb468a2ea1a
ppc64le
gnutls-3.8.10-3.el10_1.ppc64le.rpm SHA-256: 06b5f534cffe61b966db9ab3ae80084a07838e4b06118f88651d938700790015
gnutls-c++-3.8.10-3.el10_1.ppc64le.rpm SHA-256: c2f1455f150dd361269f3e0db4339e2907783cd0ee4ebc9b9e6260426ff983c5
gnutls-c++-debuginfo-3.8.10-3.el10_1.ppc64le.rpm SHA-256: d629292b581b66499ccdd9587d436e8f33018c84eccde99d8217f7e9518c7d58
gnutls-c++-debuginfo-3.8.10-3.el10_1.ppc64le.rpm SHA-256: d629292b581b66499ccdd9587d436e8f33018c84eccde99d8217f7e9518c7d58
gnutls-dane-3.8.10-3.el10_1.ppc64le.rpm SHA-256: 63e9246f292760113d167a7e1e440f2ecf606766ad57f25ea74029942416dd58
gnutls-dane-debuginfo-3.8.10-3.el10_1.ppc64le.rpm SHA-256: a74bf72ffc9a2a381ca1bc90dbea4f6b12155b8bea3de2c795bf5af79c7fff2f
gnutls-dane-debuginfo-3.8.10-3.el10_1.ppc64le.rpm SHA-256: a74bf72ffc9a2a381ca1bc90dbea4f6b12155b8bea3de2c795bf5af79c7fff2f
gnutls-debuginfo-3.8.10-3.el10_1.ppc64le.rpm SHA-256: cb4586cbbf1f9c5e71dc3e77f29515f6f30391ae978592f8fc6a3aea3c84bb23
gnutls-debuginfo-3.8.10-3.el10_1.ppc64le.rpm SHA-256: cb4586cbbf1f9c5e71dc3e77f29515f6f30391ae978592f8fc6a3aea3c84bb23
gnutls-debugsource-3.8.10-3.el10_1.ppc64le.rpm SHA-256: cbe62c384ca5248cf6c21b11e4afca62ca38025a23b4ff5c45414f5b7a3ba27e
gnutls-debugsource-3.8.10-3.el10_1.ppc64le.rpm SHA-256: cbe62c384ca5248cf6c21b11e4afca62ca38025a23b4ff5c45414f5b7a3ba27e
gnutls-devel-3.8.10-3.el10_1.ppc64le.rpm SHA-256: e41fb5087238ee8aa3ca9ea5dd6bf5d49f288da7e9000527a8454e6b65382316
gnutls-fips-3.8.10-3.el10_1.ppc64le.rpm SHA-256: 06c4dc7e41a75a46ba21ecc28dfa68a0d4d5017a22eb344e7d9491db5ba7dfd5
gnutls-utils-3.8.10-3.el10_1.ppc64le.rpm SHA-256: 31d8d24584846b3b08d49c280bf15cf754acbe7885816223a402bc826dc67f83
gnutls-utils-debuginfo-3.8.10-3.el10_1.ppc64le.rpm SHA-256: c27904d49c0bf101829d5aff0e987c1b91a4d8737275ab9f105858cfcf5002f9
gnutls-utils-debuginfo-3.8.10-3.el10_1.ppc64le.rpm SHA-256: c27904d49c0bf101829d5aff0e987c1b91a4d8737275ab9f105858cfcf5002f9

Red Hat Enterprise Linux for ARM 64 10

SRPM
gnutls-3.8.10-3.el10_1.src.rpm SHA-256: 0b3ceb3a84a45ac199e9e452f53c358ffa26fa9f881e006290c38cb468a2ea1a
aarch64
gnutls-3.8.10-3.el10_1.aarch64.rpm SHA-256: 47372e29d11e90eadca831d9ec8eb5c3db8d5a7316ee64ab2bea0688b3559e49
gnutls-c++-3.8.10-3.el10_1.aarch64.rpm SHA-256: 0cbdd402749029256b09302dea3b9389342b190932f8a2dc2a871c316e068cd4
gnutls-c++-debuginfo-3.8.10-3.el10_1.aarch64.rpm SHA-256: 87ac61861a5a4831b6287c2dbbbdb9758ee1eac8d76230c0bacf4e9f485d4db4
gnutls-c++-debuginfo-3.8.10-3.el10_1.aarch64.rpm SHA-256: 87ac61861a5a4831b6287c2dbbbdb9758ee1eac8d76230c0bacf4e9f485d4db4
gnutls-dane-3.8.10-3.el10_1.aarch64.rpm SHA-256: 8a0436599513650318d1f7b2a1d524e2d1160babc1322f4cfb710c37a912f8c9
gnutls-dane-debuginfo-3.8.10-3.el10_1.aarch64.rpm SHA-256: e69fc250e916bf67e1f42968cb73c8a56a6ef05f2fa16e828a12cee3443da3f7
gnutls-dane-debuginfo-3.8.10-3.el10_1.aarch64.rpm SHA-256: e69fc250e916bf67e1f42968cb73c8a56a6ef05f2fa16e828a12cee3443da3f7
gnutls-debuginfo-3.8.10-3.el10_1.aarch64.rpm SHA-256: 905b6dd4892c7b5778558f7750d3c241f7bcfa0d34c36be91527f59f3f14b29c
gnutls-debuginfo-3.8.10-3.el10_1.aarch64.rpm SHA-256: 905b6dd4892c7b5778558f7750d3c241f7bcfa0d34c36be91527f59f3f14b29c
gnutls-debugsource-3.8.10-3.el10_1.aarch64.rpm SHA-256: 572ffcaaae1dff2561f6dc7cc4a62c50d130f77338cb199c2b013a4b7d3cf1d8
gnutls-debugsource-3.8.10-3.el10_1.aarch64.rpm SHA-256: 572ffcaaae1dff2561f6dc7cc4a62c50d130f77338cb199c2b013a4b7d3cf1d8
gnutls-devel-3.8.10-3.el10_1.aarch64.rpm SHA-256: 62eb790ea43f7b5d7e2582031601be0ed4c2a8974b24b2c1f022049034b58ae2
gnutls-fips-3.8.10-3.el10_1.aarch64.rpm SHA-256: 111c1dc65187eb87c8139c22ebd50f2df344ed85eca8bae89c2bf7f06efbb51a
gnutls-utils-3.8.10-3.el10_1.aarch64.rpm SHA-256: d03c4afad1a5777c201818b2b482b4e17cf0f960970aece525b2d6305965c104
gnutls-utils-debuginfo-3.8.10-3.el10_1.aarch64.rpm SHA-256: b08813784c3c777e4dfb46fa8f0cadacb4ca61a4105a1ebfe8bed923f04c3707
gnutls-utils-debuginfo-3.8.10-3.el10_1.aarch64.rpm SHA-256: b08813784c3c777e4dfb46fa8f0cadacb4ca61a4105a1ebfe8bed923f04c3707

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility