Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2259 articles · 131226 vulns · 38/41 feeds (7d)
← Back to list
7.5
CVE-2026-33845PATCHED
Red Hat · Red Hat Enterprise Linux 10

Gnutls: gnutls: denial of service via dtls zero-length fragment

Description

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.

Affected Products

VendorProductVersions
Red HatRed Hat Enterprise Linux 100

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
red hatred hat enterprise linuxmitre_affected90%
red hatred hat openshift containermitre_affected90%
red hatred hat hardened imagesmitre_affected90%

References

  • https://access.redhat.com/errata/RHSA-2026:13274(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/security/cve/CVE-2026-33845(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2450624(issue-tracking, x_refsource_REDHAT)

Related News (1 articles)

Tier C
VulDB3d ago
CVE-2026-33845 | GnuTLS DTLS Handshake integer underflow
→ No new info (linked only)
CVSS 3.17.5 NONE
CISA KEV❌ No
Actively exploited❌ No
Patch available
3.8.13-1.hum1
CWECWE-191
PublishedApr 30, 2026
Last enriched3d agov2
Trending Score18
Source articles1
Independent1
Info Completeness7/14
Missing: versions, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-33846EXP
Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassembly
Trending: 50
NONECVE-2026-7500EXP
Org.keycloak.keycloak-services: improper access control on keycloak server when the account account api feature is disabled
Trending: 50
MEDIUMPRE-CVE
Multiple Denial of Service Vulnerabilities in Red Hat OpenShift Container Platform
Trending: 23
NONECVE-2026-2625
Rust-rpm-sequoia: rust-rpm-sequoia: denial of service via crafted rpm file during signature verification
Trending: 20
NONECVE-2026-7309
Openshift-controller-manager: openshift container platform: information disclosure via environment variable injection
Trending: 17

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 30, 2026
Discovered by ZDM
Apr 30, 2026
Updated: cvssEstimate
Apr 30, 2026
Patch Available
May 4, 2026

Version History

v2
Last enriched 3d ago
v2Tier C3d ago

Updated description with more technical detail, changed severity to HIGH, and set CVSS estimate to 7.5.

cvssEstimate
via VulDB
v13d ago

Initial creation