REDHAT-BUG-2467678: Medium severity GnuTLS libgnutls vulnerability
Published May 7, 2026
·Updated
libgnutls: Fix off-by-one in PKCS#12 bag element bounds check Appending to a PKCS#12 bag that already contained 32 elements could write past the bag's internal array. Reported by Zou Dikai.
Affected Software
1 affected component
GnuTLS libgnutls
Event History
May 7, 2026
Data Sourced
via Red Hat·10:54 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2467678?
The severity of REDHAT-BUG-2467678 is classified as medium with a score of 4.
2
What is the cause of the vulnerability REDHAT-BUG-2467678?
The vulnerability REDHAT-BUG-2467678 is caused by an off-by-one error in bounds checking of PKCS#12 bag elements in the libgnutls library.
3
How do I fix REDHAT-BUG-2467678?
To fix REDHAT-BUG-2467678, you need to update the GnuTLS library to a patched version that addresses the off-by-one vulnerability.
4
What impact does REDHAT-BUG-2467678 have on affected systems?
The impact of REDHAT-BUG-2467678 can lead to potential memory corruption due to writing past the bounds of the PKCS#12 bag array.
5
Who reported the REDHAT-BUG-2467678 vulnerability?
The vulnerability REDHAT-BUG-2467678 was reported by Zou Dikai.