GHSA-6452-5wg5-m56rLowCVSS 3.7

A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not...

Published
June 1, 2026
Last Modified
June 1, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.

🔗 References (5)