Description

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.

INFO

Published Date :

2026-04-30T17:41:34.076Z

Last Modified :

2026-05-04T12:54:18.629Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2026-33845 vulnerability.

Vendors Products
Gnu
  • Gnutls
Redhat
  • Enterprise Linux
  • Hardened Images
  • Hummingbird
  • Openshift
  • Openshift Container Platform

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact