CVE-2026-1584 @ morris
Status
new
Priority
6.06
Match score
3.0
Risk
DoS
Remote
CVSS
7.5 HIGH
Reason
cpe: gnutls; pkgs: gnutls; version: unknown (gnutls-3.3.29-9.el7_6.tuxcare.els5); risk:dos
Created
2026-08-22T10:15:31Z
Updated
2026-08-22T10:15:31Z
Package interrogation (copy)
Run on the host — click to copy a command. RPM
| Package | Commands |
|---|---|
| gnutls-3.3.29-9.el7_6.tuxcare.els5) |
Inventory lookup
Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.
Suggestions: gnutls
| System | Matches | Ticket for CVE-2026-1584 | |
|---|---|---|---|
| Library | libcurl3-gnutls 7.52.1-5+deb9u16; libgnutls-deb0-28 3.3.8-6+deb8u7; libgnutls-openssl27 3.5.8-5+deb9u6; libgnutls30 3.5.8-5+deb9u6 | new open | |
| Saiph | libcurl3-gnutls 7.64.0-4+deb10u9; libgnutls-deb0-28 3.3.8-6+deb8u6; libgnutls-openssl27 3.6.7-4+deb10u12; libgnutls30 3.6.7-4+deb10u12 | new open | |
| morris | gnutls 3.3.29 | new open | |
| mufasa | gnutls 3.3.29 | new open | |
| Archive | libgnutls30 3.6.7-4+deb10u12 | none | |
| Bullseye | libcurl3-gnutls 7.74.0-1.3+deb11u16; libgnutls30 3.7.1-5+deb11u10 | none | |
| Helios | libcurl3-gnutls 7.74.0-1.3+deb11u16; libgnutls30 3.7.1-5+deb11u10 | none | |
| Janus | libcurl3-gnutls 7.64.0-4+deb10u9; libgnutls30 3.6.7-4+deb10u12 | none | |
| Matrix | libcurl3-gnutls 7.88.1-10+deb12u15; libgnutls-dane0 3.7.9-2+deb12u7; libgnutls30 3.7.9-2+deb12u7 | none | |
| Silk | libcurl3-gnutls 7.88.1-10+deb12u15; libgnutls30 3.7.9-2+deb12u7 | none |
Same product CVEs in your queue
Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.
| CVE | CVSS | KEV | Systems | Status | Matched | Already related | |
|---|---|---|---|---|---|---|---|
| CVE-2026-33845 | 7.5 | Library, Saiph, morris, mufasa | accepted_risk, does_not_affect | gnutls | — | ||
| CVE-2026-42009 | 7.5 | Library, Matrix, Saiph, morris, mufasa | not_applicable | gnutls | → CVE-2026-42010 | ||
| CVE-2026-42010 | 7.1 | Library, Matrix, Saiph, morris, mufasa | not_applicable | gnutls | — |
Related CVE (same fix)
Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.
Host OS / kernel
OS
CloudLinux release 7.9 (Boris Yegorov)
(7.9)
· cloudlinux
Arch
x86_64
kernel_release
uname -r → 3.10.0-962.3.2.lve1.5.89.el7.x86_64kernel_version
uname -v → #1 SMP Thu Jul 9 15:55:31 UTC 2026For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.
Same CVE on other hosts
Open the ticket for this CVE on another system.
| System | Status | Priority | Updated | |
|---|---|---|---|---|
| mufasa | new | 6.06 | 2026-08-22T10:15:31Z | Open |
| Library | new | 1.47 | 2026-08-22T10:15:31Z | Open |
| Saiph | new | 0.48 | 2026-08-22T10:15:31Z | Open |
Description
A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value during the TLS handshake. This can lead to a NULL pointer dereference, causing the server to crash and resulting in a remote Denial of Service (DoS) condition.
Update status
Add note only
References
- https://access.redhat.com/errata/RHSA-2026:7477
- https://access.redhat.com/security/cve/CVE-2026-1584
- https://bugzilla.redhat.com/show_bug.cgi?id=2435258
- https://access.redhat.com/errata/RHSA-2026:7477
- https://access.redhat.com/security/cve/CVE-2026-1584
- https://bugzilla.redhat.com/show_bug.cgi?id=2435258
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1584.json
NVD: CVE-2026-1584