CVE-2020-13777: Canonical Ubuntu Linux

High severity, CVSS 7.4. EPSS: 22.3% chance of exploitation in the next 30 days.

GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authentication bypass in TLS 1.3). The earliest affected version is 3.6.4 (2018-09-24) because of an error in a 2018-09-18 commit. Until the first key rotation, the TLS server always uses wrong data in place of an encryption key derived from an application.

Affected products

  • Canonical Ubuntu Linux: version 19.10 only; version 20.04 only
  • Debian Debian Linux: version 10.0 only
  • Fedoraproject Fedora: version 31 only; version 32 only
  • GNU Gnutls: from 3.6.0, before 3.6.14 (fixed in 3.6.14)

Published 2020-06-04. Last modified 2026-06-17.