CVE-2024-28835: Red Hat Enterprise Linux 10
Medium severity, CVSS 5.0. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command.
Affected products
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9: before 0:3.7.6-23.el9_3.4 (fixed in 0:3.7.6-23.el9_3.4); before 0:3.8.3-4.el9_4 (fixed in 0:3.8.3-4.el9_4)
- Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support: before 0:3.7.6-21.el9_2.3 (fixed in 0:3.7.6-21.el9_2.3)
Published 2024-03-21. Last modified 2026-07-03.