Security update for gnutls
| Announcement ID: | SUSE-SU-2026:0829-1 |
|---|---|
| Release Date: | 2026-03-05T15:17:14Z |
| Rating: | moderate |
| References: | |
| Cross-References: | |
| CVSS scores: |
|
| Affected Products: |
|
An update that solves one vulnerability, contains two features and has one security fix can now be installed.
Description:
This update for gnutls fixes the following issues:
Security issue:
- CVE-2025-14831: excessive resource consumption when verifying specially crafted malicious certificates containing a large number of name constraints and subject alternative names (bsc#1257960).
Other updates and bugfixes:
- update libgnutls package to avoid binder getting calculated with SHA256 (bsc#1258083, jsc#PED-15752, jsc#PED-15753).
- lib/psk: Add gnutls_psk_allocate_{client,server}_credentials2
- tests/psk-file: Add testing for _credentials2 functions
- lib/psk: add null check for binder algo
- pre_shared_key: fix memleak when retrying with different binder algo
- pre_shared_key: add null check on pskcred
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
openSUSE Leap 15.6
zypper in -t patch SUSE-2026-829=1 openSUSE-SLE-15.6-2026-829=1 -
Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-829=1
Package List:
-
openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586)
- libgnutlsxx-devel-3.8.3-150600.4.17.1
- libgnutlsxx30-3.8.3-150600.4.17.1
- libgnutlsxx30-debuginfo-3.8.3-150600.4.17.1
- gnutls-3.8.3-150600.4.17.1
- gnutls-debugsource-3.8.3-150600.4.17.1
- libgnutls-devel-3.8.3-150600.4.17.1
- libgnutls30-debuginfo-3.8.3-150600.4.17.1
- gnutls-debuginfo-3.8.3-150600.4.17.1
- libgnutls30-3.8.3-150600.4.17.1
-
openSUSE Leap 15.6 (x86_64)
- libgnutls30-32bit-3.8.3-150600.4.17.1
- libgnutls-devel-32bit-3.8.3-150600.4.17.1
- libgnutls30-32bit-debuginfo-3.8.3-150600.4.17.1
-
openSUSE Leap 15.6 (aarch64_ilp32)
- libgnutls30-64bit-3.8.3-150600.4.17.1
- libgnutls-devel-64bit-3.8.3-150600.4.17.1
- libgnutls30-64bit-debuginfo-3.8.3-150600.4.17.1
-
Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
- libgnutlsxx-devel-3.8.3-150600.4.17.1
- libgnutlsxx30-3.8.3-150600.4.17.1
- libgnutlsxx30-debuginfo-3.8.3-150600.4.17.1
- gnutls-3.8.3-150600.4.17.1
- gnutls-debugsource-3.8.3-150600.4.17.1
- libgnutls-devel-3.8.3-150600.4.17.1
- libgnutls30-debuginfo-3.8.3-150600.4.17.1
- gnutls-debuginfo-3.8.3-150600.4.17.1
- libgnutls30-3.8.3-150600.4.17.1
-
Basesystem Module 15-SP7 (x86_64)
- libgnutls30-32bit-3.8.3-150600.4.17.1
- libgnutls30-32bit-debuginfo-3.8.3-150600.4.17.1