CVE-2024-0567: Debian Linux
High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.
Affected products
- Debian Debian Linux: version 11.0 only
- Fedoraproject Fedora: version 38 only; version 39 only
- GNU Gnutls: from 3.7.0, before 3.8.3 (fixed in 3.8.3)
- Netapp Active Iq Unified Manager: affected versions not specified
Published 2024-01-16. Last modified 2026-06-17.