CVE-2026-33846: Red Hat Cert Manager Support For Red Hat Openshift Release 1.20
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.
Affected products
- Red Hat Cert Manager Support For Red Hat Openshift Release 1.20: before 1790598593 (fixed in 1790598593)
- Red Hat Red Hat Ai Inference Server 3.2: before 1782951051 (fixed in 1782951051); before 1782951012 (fixed in 1782951012); before 1782951244 (fixed in 1782951244)
- Red Hat Red Hat Discovery 2: before 1782159791 (fixed in 1782159791); before 1782166952 (fixed in 1782166952)
- Red Hat Red Hat Enterprise Linux 10: before 0:3.8.10-4.el10_2 (fixed in 0:3.8.10-4.el10_2)
- Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support: before 0:3.8.9-9.el10_0.19 (fixed in 0:3.8.9-9.el10_0.19)
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support: before 0:3.3.29-9.el7_9.1 (fixed in 0:3.3.29-9.el7_9.1)
- Red Hat Red Hat Enterprise Linux 8: before 0:3.6.16-8.el8_10.6 (fixed in 0:3.6.16-8.el8_10.6)
- Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support: before 0:3.6.14-10.el8_4.1 (fixed in 0:3.6.14-10.el8_4.1); before 0:4.13-3.el8_4.1 (fixed in 0:4.13-3.el8_4.1)
- Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On: before 0:3.6.14-10.el8_4.1 (fixed in 0:3.6.14-10.el8_4.1); before 0:4.13-3.el8_4.1 (fixed in 0:4.13-3.el8_4.1)
- Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: before 0:3.6.16-5.el8_6.5 (fixed in 0:3.6.16-5.el8_6.5); before 0:4.13-3.el8_6.2 (fixed in 0:4.13-3.el8_6.2)
- Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On: before 0:3.6.16-5.el8_6.5 (fixed in 0:3.6.16-5.el8_6.5); before 0:4.13-3.el8_6.2 (fixed in 0:4.13-3.el8_6.2)
- Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service: before 0:3.6.16-7.el8_8.4 (fixed in 0:3.6.16-7.el8_8.4); before 0:4.13-4.el8_8.1 (fixed in 0:4.13-4.el8_8.1)
- Red Hat Red Hat Enterprise Linux 8.8 Update Services For SAP Solutions: before 0:3.6.16-7.el8_8.4 (fixed in 0:3.6.16-7.el8_8.4); before 0:4.13-4.el8_8.1 (fixed in 0:4.13-4.el8_8.1)
- Red Hat Red Hat Enterprise Linux 9: before 0:3.8.10-4.el9_8 (fixed in 0:3.8.10-4.el9_8)
- Red Hat Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions: before 0:3.7.6-21.el9_2.7 (fixed in 0:3.7.6-21.el9_2.7)
- Red Hat Red Hat Enterprise Linux 9.4 Update Services For SAP Solutions: before 0:3.8.3-4.el9_4.6 (fixed in 0:3.8.3-4.el9_4.6)
- Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support: before 0:3.8.3-6.el9_6.4 (fixed in 0:3.8.3-6.el9_6.4)
- Red Hat Red Hat Hardened Images: before 3.8.13-1.hum1 (fixed in 3.8.13-1.hum1)
- Red Hat Red Hat Openshift Ai 3.4: before 1790703542 (fixed in 1790703542)
- Red Hat Red Hat Openshift Container Platform 4
- Red Hat Red Hat Openshift Container Platform 4.12: before 412.86.202608241157-0 (fixed in 412.86.202608241157-0)
- Red Hat Red Hat Openshift Container Platform 4.13: before 413.92.202609080414-0 (fixed in 413.92.202609080414-0)
- Red Hat Red Hat Openshift Container Platform 4.14: before 414.92.202608172040-0 (fixed in 414.92.202608172040-0)
- Red Hat Red Hat Openshift Container Platform 4.15: before 415.92.202608180329-0 (fixed in 415.92.202608180329-0)
- and 5 more
Published 2026-05-04. Last modified 2026-10-08.