← Vulnerability feed

Vulnerability record · CVE-2018-16868 · published 3 December 2018

CVE-2018-16868: Gnutls observable discrepancy vulnerability

Gnu · Gnutls

A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.

5.6 CVSS 3.1 Medium EPSS 0.58% · top 54.4% CWE-203 · Observable discrepancy
5.6CVSS 3.1 base score, v2 3.3
0.58%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.

CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://cat.eyalro.net/ Technical DescriptionThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00017.html Broken LinkMailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00068.html Broken LinkMailing ListThird Party Advisory
http://www.securityfocus.com/bid/106080 Third Party AdvisoryVDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16868 Issue TrackingThird Party Advisory
http://cat.eyalro.net/ Technical DescriptionThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00017.html Broken LinkMailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00068.html Broken LinkMailing ListThird Party Advisory
http://www.securityfocus.com/bid/106080 Third Party AdvisoryVDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16868 Issue TrackingThird Party Advisory

Track CVE-2018-16868 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-1948Gnutls vulnerabilityThe _gnutls_server_name_recv_params function in lib/ext_server_name.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 does not properly calculate …EPSS 12%9.8CVE-2026-42010Gnutls vulnerabilityA flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL ch…EPSS 0.94%9.8CVE-2021-20232Gnutls use after free vulnerabilityA flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potentia…EPSS 3.4%9.8CVE-2021-20231Gnutls use after free vulnerabilityA flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.EPSS 3.8%9.8CVE-2017-5337Opensuse leap memory buffer overflow vulnerabilityMultiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have uns…EPSS 6.2%9.8CVE-2017-5336Opensuse leap memory buffer overflow vulnerabilityStack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote att…EPSS 7.1%9.8CVE-2017-5334Opensuse leap double free vulnerabilityDouble free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have…EPSS 33%9.8CVE-2009-3555TLS/SSL renegotiation flaw allows plaintext injection into sessionsThe TLS protocol and SSL 3.0 do not properly bind renegotiation handshakes to the existing connection, so a man-in-the-middle can inject data that th…EPSS 87%analysed

Source: NIST National Vulnerability Database (record CVE-2018-16868), CISA KEV, FIRST EPSS (scores of 2026-10-05). This page is refreshed as NVD updates the record.