PT-2026-7242 · Unknown · Transport Layer Security 1.3

Published

2026-01-01

·

Updated

2026-05-03

·

CVE-2026-1584

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions (affected versions not specified)
Description A flaw exists related to pre-shared key (PSK) binder verification during Transport Layer Security (TLS) 1.3 resumption attempts. The issue is triggered when an invalid PSK binder value is present in the ClientHello message, potentially leading to a denial of service (DoS) condition.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2026-1584
OPENSUSE-SU-2026:10177-1
RHSA-2026:7477

Affected Products

Transport Layer Security 1.3