{"id":"SUSE-SU-2026:2115-1","summary":"Security update for gnutls","details":"This update for gnutls fixes the following issues\n\n- CVE-2026-3833: x509/name-constraints: compare domain names case-insensitive (bsc#1263707).\n- CVE-2026-5260: lib/pkcs11_privkey: guard against overreading on short ciphertexts (bsc#1263715).\n- CVE-2026-5419: gnutls_cipher_decrypt3: make PKCS#7 unpadding branch free (bsc#1263716).\n- CVE-2026-33845: buffers: switch from end_offset over to frag_length (bsc#1263704).\n- CVE-2026-33846: buffers: add more checks to DTLS reassembly (bsc#1263705).\n- CVE-2026-42009: lib/buffers: ensure packets have differing sequence numbers (bsc#1263708).\n- CVE-2026-42010: lib/auth/rsa_psk: fix binary PSK identity lookup (bsc#1263709).\n- CVE-2026-42011: x509/name_constraints: fix intersecting empty constraints (bsc#1263710).\n- CVE-2026-42012: x509/hostname-verify: make URI/SRV SAN preclude CN fallback (bsc#1263711).\n- CVE-2026-42013: x509: prevent fallback on oversized SAN (bsc#1263712).\n- CVE-2026-42014: pkcs11_write: fix UAF and leak in gnutls_pkcs11_token_set_pin (bsc#1263713).\n- CVE-2026-42015: x509/pkcs12_bag: fix off-by-one in bag element bounds chec (bsc#1263714).\n","modified":"2026-05-30T23:15:06.135164380Z","published":"2026-05-29T15:27:34Z","related":["CVE-2026-33845","CVE-2026-33846","CVE-2026-3833","CVE-2026-42009","CVE-2026-42010","CVE-2026-42011","CVE-2026-42012","CVE-2026-42013","CVE-2026-42014","CVE-2026-42015","CVE-2026-5260","CVE-2026-5419"],"upstream":["CVE-2026-33845","CVE-2026-33846","CVE-2026-3833","CVE-2026-42009","CVE-2026-42010","CVE-2026-42011","CVE-2026-42012","CVE-2026-42013","CVE-2026-42014","CVE-2026-42015","CVE-2026-5260","CVE-2026-5419"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262115-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263704"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263705"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263707"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263708"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263709"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263710"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263711"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263712"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263713"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263714"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263715"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263716"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33845"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33846"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3833"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42009"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42010"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42011"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42012"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42013"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42014"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42015"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-5260"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-5419"}],"schema_version":"1.7.5"}