CVE-2026-1584
HIGHA flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value during the TLS handshake. This can lead to a NULL pointer dereference, causing the server to crash and resulting in a remote Denial of Service (DoS) condition.
Published: 4/9/2026Modified: 9/1/2026
Related Intelligence (0)
No articles currently reference this CVE.
References (7)
https://access.redhat.com/errata/RHSA-2026:7477https://access.redhat.com/security/cve/CVE-2026-1584Vendor Advisoryhttps://bugzilla.redhat.com/show_bug.cgi?id=2435258Issue TrackingVendor Advisoryhttps://access.redhat.com/errata/RHSA-2026:7477https://access.redhat.com/security/cve/CVE-2026-1584Vendor Advisoryhttps://bugzilla.redhat.com/show_bug.cgi?id=2435258Issue TrackingVendor Advisoryhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1584.json