Back to CVE List

CVE-2026-5260

HIGH SEVERITY

CVSS Score & Metrics

Base Score
8.2 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

Vulnerability Description

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-1284
Source
NVD

External References

Discussion (0)

Add Comment

No comments yet. Be the first!