Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:43575 - Security Advisory
Issued:
2026-07-22
Updated:
2026-07-22

RHSA-2026:43575 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: gnutls security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for gnutls is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS.

Security Fix(es):

  • gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison (CVE-2026-3833)
  • gnutls: gnutls: Security bypass due to incorrect name constraint handling (CVE-2026-42011)
  • gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs (CVE-2026-42012)
  • gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name (CVE-2026-42013)
  • gnutls: Fix use-after-free in gnutls_pkcs11_token_set_pin (CVE-2026-42014)
  • gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling (CVE-2026-42015)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le

Fixes

  • BZ - 2445763 - CVE-2026-3833 gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison
  • BZ - 2467437 - CVE-2026-42011 gnutls: gnutls: Security bypass due to incorrect name constraint handling
  • BZ - 2467441 - CVE-2026-42012 gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs
  • BZ - 2467448 - CVE-2026-42013 gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name
  • BZ - 2467451 - CVE-2026-42014 gnutls: gnutls: Use-after-free in gnutls_pkcs11_token_set_pin
  • BZ - 2467678 - CVE-2026-42015 gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling

CVEs

  • CVE-2026-3833
  • CVE-2026-42011
  • CVE-2026-42012
  • CVE-2026-42013
  • CVE-2026-42014
  • CVE-2026-42015

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - Extended Life Cycle Support 7

SRPM
gnutls-3.3.29-9.el7_9.2.src.rpm SHA-256: a1bc1f197a99f68643624d77a6486e8ebfc17fa6bbe6d6335e34a45a685f2cd5
x86_64
gnutls-3.3.29-9.el7_9.2.i686.rpm SHA-256: c66555e6e94ba315a583dc16e0dd1b9c31808cf056c2378558c0aca8c28e0869
gnutls-3.3.29-9.el7_9.2.x86_64.rpm SHA-256: c67d0116ab5706a7249cb4780261f0b735309fad25528c97944567837da5f669
gnutls-c++-3.3.29-9.el7_9.2.i686.rpm SHA-256: f659735f9d5098d78b1dbc2b1d2576db352afcc4f7ad4dcc4c3a7442f0ffdac4
gnutls-c++-3.3.29-9.el7_9.2.x86_64.rpm SHA-256: 051306b4d696fd6c4a7adaa3fd107bde47f60ea0f41d40723f71e245724688be
gnutls-dane-3.3.29-9.el7_9.2.i686.rpm SHA-256: 1ef77bc8be7775ef7ef0172d8ffce10ac048825cf68864340a65585795eb695f
gnutls-dane-3.3.29-9.el7_9.2.x86_64.rpm SHA-256: 131c246448191940e4c67ed9b870abad4a17c616bebe1a9ed04b0b68e00924f8
gnutls-debuginfo-3.3.29-9.el7_9.2.i686.rpm SHA-256: 1d43d53f5b3008f025e557d91107353a67deb129a87f6dc17c046237c53175f4
gnutls-debuginfo-3.3.29-9.el7_9.2.x86_64.rpm SHA-256: 2c8311c0785330553b8b73e85eece2d9613b8ddaa8417c2fb476ce9601f0db1a
gnutls-devel-3.3.29-9.el7_9.2.i686.rpm SHA-256: 6bfdc7b460ad3ffac404058a931857891bad0f55ea3287c60c59abea3c03850e
gnutls-devel-3.3.29-9.el7_9.2.x86_64.rpm SHA-256: d4a88a967492a54ff0365cfe8da4ae5b0061bbeb37b2fbd56d7c773b9940406e
gnutls-utils-3.3.29-9.el7_9.2.x86_64.rpm SHA-256: e0bf037345d46587cfadab272f8fc6c70fdab7471ca66dc5e9bdc9ba442c8f0e

Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7

SRPM
gnutls-3.3.29-9.el7_9.2.src.rpm SHA-256: a1bc1f197a99f68643624d77a6486e8ebfc17fa6bbe6d6335e34a45a685f2cd5
s390x
gnutls-3.3.29-9.el7_9.2.s390.rpm SHA-256: 1267e7ff96dda6c7d01eb79a5377934bd03c541f71d33f14016f78920128fca0
gnutls-3.3.29-9.el7_9.2.s390x.rpm SHA-256: 1b64e53972fddb1ad4704a7fbaaa8de574bce477de3f984f5058dcd74b4bd47c
gnutls-c++-3.3.29-9.el7_9.2.s390.rpm SHA-256: 2188a2f38429fd9b464cd50edf017ad2f6914e7b9a9eb9e5de2248df19a2c089
gnutls-c++-3.3.29-9.el7_9.2.s390x.rpm SHA-256: 5e6b710786f1ac6cba61d267ec0783d9e06eeeb2c42a24c7ecf5ba2197188878
gnutls-dane-3.3.29-9.el7_9.2.s390.rpm SHA-256: 84e9a9cd939da24ad416b7556a456b94de2e8e09de418365120b77e01b09cd37
gnutls-dane-3.3.29-9.el7_9.2.s390x.rpm SHA-256: 25756a5e2743dccc2512e054016bad28671cfeff7516fac36208d8adfab254c8
gnutls-debuginfo-3.3.29-9.el7_9.2.s390.rpm SHA-256: 1f5d194a81b1b879963c80615637d78724b06ff227f6c837ff14cb403585a390
gnutls-debuginfo-3.3.29-9.el7_9.2.s390x.rpm SHA-256: 0172db9f39604b91728e80681528d3a045f2b68fc403747a2c1ce646320f4c9e
gnutls-devel-3.3.29-9.el7_9.2.s390.rpm SHA-256: 1f4813a620187bedd1a8e6bbd9448a4c4c03dc3d3fe859b22b344ca9e9ba024c
gnutls-devel-3.3.29-9.el7_9.2.s390x.rpm SHA-256: f8321f5e411a26febe4ca57d59d02dda05e95697b3d8ba509575146363138f82
gnutls-utils-3.3.29-9.el7_9.2.s390x.rpm SHA-256: dc9b9c5e6fe0842b684e36504068c61260a66c68a0a540591c5f786acd17ef4f

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7

SRPM
gnutls-3.3.29-9.el7_9.2.src.rpm SHA-256: a1bc1f197a99f68643624d77a6486e8ebfc17fa6bbe6d6335e34a45a685f2cd5
ppc64
gnutls-3.3.29-9.el7_9.2.ppc.rpm SHA-256: 042fb36df57dd857f7fbca5db0c255e20f31cdf71fd8c6d0f3ba1e98eb0fc862
gnutls-3.3.29-9.el7_9.2.ppc64.rpm SHA-256: a1ce18044091d74c44d0d12f3a9e9435d10d312cacd1c6a5fde0003614d92f03
gnutls-c++-3.3.29-9.el7_9.2.ppc.rpm SHA-256: bd5b4b5c4f15d41f20ce70ad4ed3f898c56edb4055e118e8acfdd49aa71b13e2
gnutls-c++-3.3.29-9.el7_9.2.ppc64.rpm SHA-256: 1245511e2efa5c4c9a6d5a145f918e74cfa288b09e811ba216c2433d6170ca8a
gnutls-dane-3.3.29-9.el7_9.2.ppc.rpm SHA-256: cbc92050a3e2d7634851fe216df09f6c39f11de720d32db9152c0dfedc97b84d
gnutls-dane-3.3.29-9.el7_9.2.ppc64.rpm SHA-256: 121e8fc0a0b8f008a5648354bc70e953c622e03ecb99b3356fdb79da15b4731a
gnutls-debuginfo-3.3.29-9.el7_9.2.ppc.rpm SHA-256: b335e47af5011eb8304a1f6bb4fa07f15b81bad7958163297743713ebe8f769d
gnutls-debuginfo-3.3.29-9.el7_9.2.ppc64.rpm SHA-256: e417beb74000c60e2acf7ed236f348ffbdeb86e2d387b8e5ea4da40284cfc8a1
gnutls-devel-3.3.29-9.el7_9.2.ppc.rpm SHA-256: d22a0741def3c6b9091cf926cad5292167804480d94f2208963edce3770b9fcf
gnutls-devel-3.3.29-9.el7_9.2.ppc64.rpm SHA-256: 5892362f4a8ec2ca52ea410bcd06cdaae66fc78efc09a0e52cc444f0494a9347
gnutls-utils-3.3.29-9.el7_9.2.ppc64.rpm SHA-256: 87d08c1f5a960c341206a7c4a005ce07a06cd32709b2b7a66cf71daa8e0df074

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7

SRPM
gnutls-3.3.29-9.el7_9.2.src.rpm SHA-256: a1bc1f197a99f68643624d77a6486e8ebfc17fa6bbe6d6335e34a45a685f2cd5
ppc64le
gnutls-3.3.29-9.el7_9.2.ppc64le.rpm SHA-256: 847e7f3b9a8ef2ce418ccef17b738c448e240adacf1ebcc170001c1ff3db06e0
gnutls-c++-3.3.29-9.el7_9.2.ppc64le.rpm SHA-256: b69c6d42d9e4ce3c665ced347476232ea995339aec9d870d9332113c6215a737
gnutls-dane-3.3.29-9.el7_9.2.ppc64le.rpm SHA-256: edf368c2b7ce7d7dd51de63456cb9d5ad8e0e424da8a26d9102530b2dd5dbb46
gnutls-debuginfo-3.3.29-9.el7_9.2.ppc64le.rpm SHA-256: de3d693c57cc166ed0ea18bd42ead69b55c39c3a538cf8c8e47f7341bd0e2876
gnutls-devel-3.3.29-9.el7_9.2.ppc64le.rpm SHA-256: a92cd126a75e4bcf96891d122b8f49513b56cb4e6e1178ef9d952e929dfcd707
gnutls-utils-3.3.29-9.el7_9.2.ppc64le.rpm SHA-256: 49873428082f4ceadc839cfeca07d8a9fb00e8dcdbb78737449037183843ed2b

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility