VDB
RHSA-2026%3A5606
RHSA-2026%3A5606
PUBLISHED
CVSS 4 MEDIUM
A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a fixed-size stack buffer. This programming error can cause the application using GnuTLS to crash or, in certain conditions, be exploited for code execution. As a result, systems or applications relying on GnuTLS may be vulnerable to a denial of service or local privilege escalation attacks.
Risk Scores
CVSS 3.1
4
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/rhceph/rhceph-8-rhel9@sha256:2a73d2ab438040547d61bf4257a50a3d33cb5e74f40d372a865fe0db9ba9d5af_arm64 as a component of Red Hat Ceph Storage 8 | *, registry.redhat.io/rhceph/rhceph-8-rhel9@sha256:2a73d2ab438040547d61bf4257a50a3d33cb5e74f40d372a865fe0db9ba9d5af_arm64, registry.redhat.io/rhceph/rhceph-8-rhel9@sha256:2a73d2ab438040547d61bf4257a50a3d33cb5e74f40d372a865fe0db9ba9d5af_arm64 |
| Red Hat | registry.redhat.io/rhceph/rhceph-8-rhel9@sha256:1160569002c25d3d349bbe41b57eeffade438853d3419edca01813227440f414_amd64 as a component of Red Hat Ceph Storage 8 | *, *, * |
| Red Hat | registry.redhat.io/rhceph/rhceph-8-rhel9@sha256:ba2480ebb7946082380496ad7b92b92560a8bb9ddcd8e2f94f0c502ce65c1d0c_ppc64le as a component of Red Hat Ceph Storage 8 | *, registry.redhat.io/rhceph/rhceph-8-rhel9@sha256:ba2480ebb7946082380496ad7b92b92560a8bb9ddcd8e2f94f0c502ce65c1d0c_ppc64le, registry.redhat.io/rhceph/rhceph-8-rhel9@sha256:ba2480ebb7946082380496ad7b92b92560a8bb9ddcd8e2f94f0c502ce65c1d0c_ppc64le |
| Red Hat | registry.redhat.io/rhceph/rhceph-8-rhel9@sha256:a0f0f9770911d6a0fc522f304942765059643193e95c9f6e505462f98a979db1_s390x as a component of Red Hat Ceph Storage 8 | *, *, * |
Timeline
- Mar 24, 2026 CVE Published
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2026:5606 advisory
- https://access.redhat.com/security/cve/CVE-2025-12801 advisory
- https://access.redhat.com/security/cve/CVE-2025-14831 advisory
- https://access.redhat.com/security/cve/CVE-2025-15281 advisory
- https://access.redhat.com/security/cve/CVE-2025-15366 advisory
- https://access.redhat.com/security/cve/CVE-2025-15367 advisory
- https://access.redhat.com/security/cve/CVE-2025-9820 advisory
- https://access.redhat.com/security/cve/CVE-2026-0861 advisory
- https://access.redhat.com/security/cve/CVE-2026-0865 advisory
- https://access.redhat.com/security/cve/CVE-2026-0915 advisory
- https://access.redhat.com/security/cve/CVE-2026-1299 advisory
- https://access.redhat.com/security/cve/CVE-2026-22695 advisory
- https://access.redhat.com/security/cve/CVE-2026-22801 advisory
- https://access.redhat.com/security/cve/CVE-2026-23490 advisory
- https://access.redhat.com/security/cve/CVE-2026-25646 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://docs.redhat.com/en/documentation/red_hat_ceph_storage/ advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_5606.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2392528 issue
- https://www.cve.org/CVERecord?id=CVE-2025-9820 advisory
…and 72 more