CVE Tracker

CVE-2026-1584 @ Saiph

Status
new
Priority
0.48
Match score
3.0
Risk
DoS Remote
CVSS
7.5 HIGH
Reason
cpe: gnutls; pkgs: gnutls-deb0-28, gnutls-openssl27; version: unknown (gnutls-deb0-28-3.3.8-6+deb8u6; gnutls-openssl27-3.6.7-4+deb10u12); risk:dos
Created
2026-08-22T10:15:31Z
Updated
2026-08-22T10:15:31Z

Package interrogation (copy)

Run on the host — click to copy a command. Debian/apt

PackageCommands
gnutls-deb0-28-3.3.8-6+deb8u6
gnutls-openssl27-3.6.7-4+deb10u12)
gnutls-deb0-28
gnutls

Inventory lookup

Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.

Clear

Suggestions: gnutls-deb0 · gnutls-openssl27 · gnutls · gnutls-deb0-28

SystemMatchesTicket for CVE-2026-1584
Library libgnutls-openssl27 3.5.8-5+deb9u6 new open
Saiph libgnutls-openssl27 3.6.7-4+deb10u12 new open

Same product CVEs in your queue

Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.

CVECVSSKEVSystemsStatus MatchedAlready related
CVE-2026-33845 7.5 Library, Saiph, morris, mufasa accepted_risk, does_not_affect gnutls
CVE-2026-42009 7.5 Library, Matrix, Saiph, morris, mufasa not_applicable gnutls → CVE-2026-42010
CVE-2026-42010 7.1 Library, Matrix, Saiph, morris, mufasa not_applicable gnutls

Related CVE (same fix)

Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.

Host OS / kernel

OS
Debian GNU/Linux 10 (buster) (10) · debian
Arch
x86_64
kernel_release
uname -r → 4.19.0-27-amd64
kernel_version
uname -v → #1 SMP Debian 4.19.316-1 (2024-06-25)

For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.

Same CVE on other hosts

Open the ticket for this CVE on another system.

System Status Priority Updated
morris new 6.06 2026-08-22T10:15:31Z Open
mufasa new 6.06 2026-08-22T10:15:31Z Open
Library new 1.47 2026-08-22T10:15:31Z Open

Description

A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value during the TLS handshake. This can lead to a NULL pointer dereference, causing the server to crash and resulting in a remote Denial of Service (DoS) condition.

Update status

Also apply to other systems with this CVE:

Add note only

Also add note on:

References

NVD: CVE-2026-1584