CVE-2026-5419
Public on 2026-05-02
Modified on 2026-05-02
Description
The PKCS#7 padding check performed during decryption was not constant-time, potentially leaking information about the padding bytes through timing differences. The issue was reported in the issue tracker as #1815 by Doria Tang of Stony Brook University.
Recommendation: To address the issue found, upgrade to GnuTLS 3.8.13 or later versions.
Recommendation: To address the issue found, upgrade to GnuTLS 3.8.13 or later versions.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | gnutls | Not Affected | ||
| Amazon Linux 2023 | gnutls | Pending Fix |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 3.7 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |