Impact
A flaw in the GNUTLS library allows a remote attacker to perform an off‑by‑one write when appending to a PKCS#12 bag that already contains 32 elements. The attacker can corrupt memory beyond the internal array of the bag. This memory corruption can trigger a denial of service or other unspecified impacts on the affected system. The weakness is a classic off‑by‑one error (CWE‑193).
Affected Systems
The vulnerability impacts Red Hat Enterprise Linux releases 6 through 10, Red Hat Hardened Images, and Red Hat OpenShift Container Platform 4. These systems include the GNUTLS library in their default package set and therefore are susceptible to the described memory corruption when a PKCS#12 bag operation is performed.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is unavailable, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it is not a known, actively exploited flaw at the time of analysis. Attackers would need remote or delegated access to a process that loads a PKCS#12 bag and supplies an input that triggers the off‑by‑one condition. Successful exploitation would result in a denial of service or potentially other impacts depending on the attacker’s goal and the system’s configuration.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN