CVE-2024-0567: Debian Linux

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.

Affected products

  • Debian Debian Linux: version 11.0 only
  • Fedoraproject Fedora: version 38 only; version 39 only
  • GNU Gnutls: from 3.7.0, before 3.8.3 (fixed in 3.8.3)
  • Netapp Active Iq Unified Manager: affected versions not specified

Published 2024-01-16. Last modified 2026-06-17.