PT-2026-47001 · Julia · Gnutls Jll
Published
2026-05-26
·
Updated
2026-05-26
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
An issue was discovered in GnuTLS before 3.6.15. A server can trigger a NULL pointer dereference in a TLS 1.3 client if a no renegotiation alert is sent with unexpected timing, and then an invalid second handshake occurs. The crash happens in the application's error handling path, where the gnutls deinit function is called after detecting a handshake failure.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gnutls Jll