Impact
The vulnerability involves the PKCS#7 padding check within GnuTLS, which is executed with a non‑constant‑time comparison. This timing side‑channel allows an attacker to deduce the value of padding bytes when decrypting data. The disclosed information leaks only padding values, which can be used in further cryptographic attacks. This flaw is cataloged as CWE‑208, resulting in an Information Exposure result with a CVSS score of 3.7.
Affected Systems
Affected distributions include Red Hat Enterprise Linux 10, 6, 7, 8, and 9, as well as Red Hat Hardened Images and Red Hat OpenShift Container Platform 4. The patch that addresses this issue has been published in the RHSA‑2026:20613 errata. The vulnerability applies to any system component that performs PKCS#7 decryption using the affected GnuTLS libraries.
Risk and Exploitability
The risk is moderate; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker to deliver crafted ciphertext to a service that decrypts it with GnuTLS and to observe timing differences. The attack is likely remote, via network traffic to a vulnerable service, though the specific attack vector is inferred from the description. No published exploit is known.
OpenCVE Enrichment
Debian DSA
Ubuntu USN