CVE-2026-5260
Red Hat Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8
A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.
- CVSS
- 8.2
- EPSS
- 0.73% 50.5% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.27