CVE-2026-5419: Red Hat Cert Manager Support For Red Hat Openshift Release 1.20

Low severity, CVSS 3.7. EPSS: 0.6% chance of exploitation in the next 30 days.

A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.

Affected products

  • Red Hat Cert Manager Support For Red Hat Openshift Release 1.20: before 1790598593 (fixed in 1790598593)
  • Red Hat Red Hat Discovery 2: before 1782159791 (fixed in 1782159791); before 1782166952 (fixed in 1782166952)
  • Red Hat Red Hat Enterprise Linux 10: before 0:3.8.10-4.el10_2 (fixed in 0:3.8.10-4.el10_2)
  • Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support: before 0:3.8.9-9.el10_0.19 (fixed in 0:3.8.9-9.el10_0.19)
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9: before 0:3.8.10-4.el9_8 (fixed in 0:3.8.10-4.el9_8)
  • Red Hat Red Hat Enterprise Linux 9.4 Update Services For SAP Solutions: before 0:3.8.3-4.el9_4.6 (fixed in 0:3.8.3-4.el9_4.6)
  • Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support: before 0:3.8.3-6.el9_6.4 (fixed in 0:3.8.3-6.el9_6.4)
  • Red Hat Red Hat Hardened Images: before 3.8.13-1.hum1 (fixed in 3.8.13-1.hum1)
  • Red Hat Red Hat Openshift Ai 3.4: before 1790703542 (fixed in 1790703542)
  • Red Hat Red Hat Openshift Container Platform 4
  • Red Hat Red Hat Update Infrastructure 5: before 1781525684 (fixed in 1781525684); before 1781525671 (fixed in 1781525671); before 1781525693 (fixed in 1781525693); before 1781525739 (fixed in 1781525739); before 1787241211 (fixed in 1787241211); before 1787135742 (fixed in 1787135742); …

Published 2026-06-01. Last modified 2026-10-02.