CVE-2019-3829: Fedoraproject Fedora

High severity, CVSS 7.5. EPSS: 59% chance of exploitation in the next 30 days.

A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is affected.

Affected products

  • Fedoraproject Fedora: affected versions not specified
  • GNU Gnutls: from 3.5.8, before 3.6.7 (fixed in 3.6.7)

Published 2019-03-27. Last modified 2026-06-17.