Information Exposure Through Timing Discrepancy in GnuTLS - CVE-2026-5419

 

Information Exposure Through Timing Discrepancy in GnuTLS - CVE-2026-5419

Published: April 30, 2026


Vulnerability identifier: #VU128580
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-5419
CWE-ID: CWE-208
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to observable timing discrepancy in PKCS#7 padding check during decryption when processing ciphertext. A remote attacker can send specially crafted ciphertext to disclose sensitive information.


Affected software

GnuTLS
Debian Linux
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
gnutls28 (Ubuntu package)
gnutls28 (Debian package)
gnutls-dane
gnutls-help
gnutls-utils
gnutls-devel
gnutls-debugsource
gnutls-debuginfo
gnutls
libgnutlsxx30-debuginfo
libgnutls30
libgnutls30-32bit-debuginfo
libgnutlsxx30
libgnutls30-32bit
libgnutls-devel-32bit
libgnutls30-64bit
libgnutls-devel-64bit
libgnutls30-64bit-debuginfo
libgnutlsxx-devel
libgnutls-devel
libgnutls30-debuginfo
gnutls (Red Hat package)

How to mitigate CVE-2026-5419

Install security update from vendor's website.

GnuTLS - update to 3.8.13
gnutls28 (Ubuntu package) - addressed in versions 3.7.3-4ubuntu1.9, 3.8.3-1.1ubuntu3.6, 3.8.9-3ubuntu2.2, 3.8.12-2ubuntu1.1
gnutls28 (Debian package) - addressed in versions 3.7.9-2+deb12u7, 3.8.9-3+deb13u4
gnutls-dane - update to 3.8.2-14
gnutls-help - update to 3.8.2-14
gnutls-utils - update to 3.8.2-14
gnutls-devel - update to 3.8.2-14
gnutls-debugsource - update to 3.8.2-14
gnutls-debuginfo - update to 3.8.2-14
gnutls - update to 3.8.2-14
libgnutlsxx30-debuginfo - update to 3.8.3-150600.4.20.1
libgnutls30 - update to 3.8.3-150600.4.20.1
libgnutls30-32bit-debuginfo - update to 3.8.3-150600.4.20.1
libgnutlsxx30 - update to 3.8.3-150600.4.20.1
libgnutls30-32bit - update to 3.8.3-150600.4.20.1
libgnutls-devel-32bit - update to 3.8.3-150600.4.20.1
libgnutls30-64bit - update to 3.8.3-150600.4.20.1
libgnutls-devel-64bit - update to 3.8.3-150600.4.20.1
libgnutls30-64bit-debuginfo - update to 3.8.3-150600.4.20.1
libgnutlsxx-devel - update to 3.8.3-150600.4.20.1
gnutls - update to 3.8.3-150600.4.20.1
gnutls-debuginfo - update to 3.8.3-150600.4.20.1
libgnutls-devel - update to 3.8.3-150600.4.20.1
libgnutls30-debuginfo - update to 3.8.3-150600.4.20.1
gnutls-debugsource - update to 3.8.3-150600.4.20.1
gnutls (Red Hat package) - update to 3.8.9-9.el10_0.19

External References

Related Security Bulletins