{
	"document":{
		"aggregate_severity":{
			"namespace":"https://nvd.nist.gov/vuln-metrics/cvss",
			"text":"High"
		},
		"category":"csaf_vex",
		"csaf_version":"2.0",
		"distribution":{
			"tlp":{
				"label":"WHITE",
				"url":"https:/www.first.org/tlp/"
			}
		},
		"lang":"en",
		"notes":[
			{
				"text":"gnutls security update",
				"category":"general",
				"title":"Synopsis"
			},
			{
				"text":"An update for gnutls is now available for openEuler-24.03-LTS-SP3",
				"category":"general",
				"title":"Summary"
			},
			{
				"text":"GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, and other required structures. The project strives to provide a secure communications back-end, simple to use and integrated with the rest of the base Linux libraries. A back-end designed to work and be secure out of the box, keeping the complexity of TLS and PKI out of application code.\n\nSecurity Fix(es):\n\nA flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.(CVE-2026-3832)\n\nA flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.(CVE-2026-42012)",
				"category":"general",
				"title":"Description"
			},
			{
				"text":"An update for gnutls is now available for openEuler-24.03-LTS-SP3.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.",
				"category":"general",
				"title":"Topic"
			},
			{
				"text":"High",
				"category":"general",
				"title":"Severity"
			},
			{
				"text":"gnutls",
				"category":"general",
				"title":"Affected Component"
			}
		],
		"publisher":{
			"issuing_authority":"openEuler security committee",
			"name":"openEuler",
			"namespace":"https://www.openeuler.org",
			"contact_details":"openeuler-security@openeuler.org",
			"category":"vendor"
		},
		"references":[
			{
				"summary":"openEuler-SA-2026-3121",
				"category":"self",
				"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3121"
			},
			{
				"summary":"CVE-2026-3832",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-3832&packageName=gnutls"
			},
			{
				"summary":"CVE-2026-42012",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-42012&packageName=gnutls"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-3832"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42012"
			},
			{
				"summary":"openEuler-SA-2026-3121 vex file",
				"category":"self",
				"url":"https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-3121.json"
			}
		],
		"title":"An update for gnutls is now available for openEuler-24.03-LTS-SP3",
		"tracking":{
			"initial_release_date":"2026-07-27T11:30:36+08:00",
			"revision_history":[
				{
					"date":"2026-07-27T11:30:36+08:00",
					"summary":"Initial",
					"number":"1.0.0"
				}
			],
			"generator":{
				"date":"2026-07-27T11:30:36+08:00",
				"engine":{
					"name":"openEuler CSAF Tool V1.0"
				}
			},
			"current_release_date":"2026-07-27T11:30:36+08:00",
			"id":"openEuler-SA-2026-3121",
			"version":"1.0.0",
			"status":"final"
		}
	},
	"product_tree":{
		"branches":[
			{
				"name":"openEuler",
				"category":"vendor",
				"branches":[
					{
						"name":"openEuler",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"openEuler-24.03-LTS-SP3",
									"name":"openEuler-24.03-LTS-SP3"
								},
								"name":"openEuler-24.03-LTS-SP3",
								"category":"product_version"
							}
						],
						"category":"product_name"
					},
					{
						"name":"aarch64",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"gnutls-3.8.2-16.oe2403sp3.aarch64.rpm",
									"name":"gnutls-3.8.2-16.oe2403sp3.aarch64.rpm"
								},
								"name":"gnutls-3.8.2-16.oe2403sp3.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"gnutls-dane-3.8.2-16.oe2403sp3.aarch64.rpm",
									"name":"gnutls-dane-3.8.2-16.oe2403sp3.aarch64.rpm"
								},
								"name":"gnutls-dane-3.8.2-16.oe2403sp3.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"gnutls-debuginfo-3.8.2-16.oe2403sp3.aarch64.rpm",
									"name":"gnutls-debuginfo-3.8.2-16.oe2403sp3.aarch64.rpm"
								},
								"name":"gnutls-debuginfo-3.8.2-16.oe2403sp3.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"gnutls-debugsource-3.8.2-16.oe2403sp3.aarch64.rpm",
									"name":"gnutls-debugsource-3.8.2-16.oe2403sp3.aarch64.rpm"
								},
								"name":"gnutls-debugsource-3.8.2-16.oe2403sp3.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"gnutls-devel-3.8.2-16.oe2403sp3.aarch64.rpm",
									"name":"gnutls-devel-3.8.2-16.oe2403sp3.aarch64.rpm"
								},
								"name":"gnutls-devel-3.8.2-16.oe2403sp3.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"gnutls-utils-3.8.2-16.oe2403sp3.aarch64.rpm",
									"name":"gnutls-utils-3.8.2-16.oe2403sp3.aarch64.rpm"
								},
								"name":"gnutls-utils-3.8.2-16.oe2403sp3.aarch64.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"src",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"gnutls-3.8.2-16.oe2403sp3.src.rpm",
									"name":"gnutls-3.8.2-16.oe2403sp3.src.rpm"
								},
								"name":"gnutls-3.8.2-16.oe2403sp3.src.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"x86_64",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"gnutls-3.8.2-16.oe2403sp3.x86_64.rpm",
									"name":"gnutls-3.8.2-16.oe2403sp3.x86_64.rpm"
								},
								"name":"gnutls-3.8.2-16.oe2403sp3.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"gnutls-dane-3.8.2-16.oe2403sp3.x86_64.rpm",
									"name":"gnutls-dane-3.8.2-16.oe2403sp3.x86_64.rpm"
								},
								"name":"gnutls-dane-3.8.2-16.oe2403sp3.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"gnutls-debuginfo-3.8.2-16.oe2403sp3.x86_64.rpm",
									"name":"gnutls-debuginfo-3.8.2-16.oe2403sp3.x86_64.rpm"
								},
								"name":"gnutls-debuginfo-3.8.2-16.oe2403sp3.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"gnutls-debugsource-3.8.2-16.oe2403sp3.x86_64.rpm",
									"name":"gnutls-debugsource-3.8.2-16.oe2403sp3.x86_64.rpm"
								},
								"name":"gnutls-debugsource-3.8.2-16.oe2403sp3.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"gnutls-devel-3.8.2-16.oe2403sp3.x86_64.rpm",
									"name":"gnutls-devel-3.8.2-16.oe2403sp3.x86_64.rpm"
								},
								"name":"gnutls-devel-3.8.2-16.oe2403sp3.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"gnutls-utils-3.8.2-16.oe2403sp3.x86_64.rpm",
									"name":"gnutls-utils-3.8.2-16.oe2403sp3.x86_64.rpm"
								},
								"name":"gnutls-utils-3.8.2-16.oe2403sp3.x86_64.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"noarch",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"gnutls-help-3.8.2-16.oe2403sp3.noarch.rpm",
									"name":"gnutls-help-3.8.2-16.oe2403sp3.noarch.rpm"
								},
								"name":"gnutls-help-3.8.2-16.oe2403sp3.noarch.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					}
				]
			}
		],
		"relationships":[
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"gnutls-3.8.2-16.oe2403sp3.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:gnutls-3.8.2-16.oe2403sp3.aarch64",
					"name":"gnutls-3.8.2-16.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"gnutls-dane-3.8.2-16.oe2403sp3.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:gnutls-dane-3.8.2-16.oe2403sp3.aarch64",
					"name":"gnutls-dane-3.8.2-16.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"gnutls-debuginfo-3.8.2-16.oe2403sp3.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:gnutls-debuginfo-3.8.2-16.oe2403sp3.aarch64",
					"name":"gnutls-debuginfo-3.8.2-16.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"gnutls-debugsource-3.8.2-16.oe2403sp3.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:gnutls-debugsource-3.8.2-16.oe2403sp3.aarch64",
					"name":"gnutls-debugsource-3.8.2-16.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"gnutls-devel-3.8.2-16.oe2403sp3.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:gnutls-devel-3.8.2-16.oe2403sp3.aarch64",
					"name":"gnutls-devel-3.8.2-16.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"gnutls-utils-3.8.2-16.oe2403sp3.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:gnutls-utils-3.8.2-16.oe2403sp3.aarch64",
					"name":"gnutls-utils-3.8.2-16.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"gnutls-3.8.2-16.oe2403sp3.src.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:gnutls-3.8.2-16.oe2403sp3.src",
					"name":"gnutls-3.8.2-16.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"gnutls-3.8.2-16.oe2403sp3.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:gnutls-3.8.2-16.oe2403sp3.x86_64",
					"name":"gnutls-3.8.2-16.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"gnutls-dane-3.8.2-16.oe2403sp3.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:gnutls-dane-3.8.2-16.oe2403sp3.x86_64",
					"name":"gnutls-dane-3.8.2-16.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"gnutls-debuginfo-3.8.2-16.oe2403sp3.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:gnutls-debuginfo-3.8.2-16.oe2403sp3.x86_64",
					"name":"gnutls-debuginfo-3.8.2-16.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"gnutls-debugsource-3.8.2-16.oe2403sp3.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:gnutls-debugsource-3.8.2-16.oe2403sp3.x86_64",
					"name":"gnutls-debugsource-3.8.2-16.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"gnutls-devel-3.8.2-16.oe2403sp3.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:gnutls-devel-3.8.2-16.oe2403sp3.x86_64",
					"name":"gnutls-devel-3.8.2-16.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"gnutls-utils-3.8.2-16.oe2403sp3.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:gnutls-utils-3.8.2-16.oe2403sp3.x86_64",
					"name":"gnutls-utils-3.8.2-16.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"gnutls-help-3.8.2-16.oe2403sp3.noarch.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:gnutls-help-3.8.2-16.oe2403sp3.noarch",
					"name":"gnutls-help-3.8.2-16.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			}
		]
	},
	"vulnerabilities":[
		{
			"cve":"CVE-2026-3832",
			"notes":[
				{
					"text":"A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP3:gnutls-3.8.2-16.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:gnutls-dane-3.8.2-16.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:gnutls-debuginfo-3.8.2-16.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:gnutls-debugsource-3.8.2-16.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:gnutls-devel-3.8.2-16.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:gnutls-utils-3.8.2-16.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:gnutls-3.8.2-16.oe2403sp3.src",
					"openEuler-24.03-LTS-SP3:gnutls-3.8.2-16.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:gnutls-dane-3.8.2-16.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:gnutls-debuginfo-3.8.2-16.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:gnutls-debugsource-3.8.2-16.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:gnutls-devel-3.8.2-16.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:gnutls-utils-3.8.2-16.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:gnutls-help-3.8.2-16.oe2403sp3.noarch"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP3:gnutls-3.8.2-16.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:gnutls-dane-3.8.2-16.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:gnutls-debuginfo-3.8.2-16.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:gnutls-debugsource-3.8.2-16.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:gnutls-devel-3.8.2-16.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:gnutls-utils-3.8.2-16.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:gnutls-3.8.2-16.oe2403sp3.src",
						"openEuler-24.03-LTS-SP3:gnutls-3.8.2-16.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:gnutls-dane-3.8.2-16.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:gnutls-debuginfo-3.8.2-16.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:gnutls-debugsource-3.8.2-16.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:gnutls-devel-3.8.2-16.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:gnutls-utils-3.8.2-16.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:gnutls-help-3.8.2-16.oe2403sp3.noarch"
					],
					"details":"gnutls security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3121"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"LOW",
						"baseScore":3.7,
						"vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP3:gnutls-3.8.2-16.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:gnutls-dane-3.8.2-16.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:gnutls-debuginfo-3.8.2-16.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:gnutls-debugsource-3.8.2-16.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:gnutls-devel-3.8.2-16.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:gnutls-utils-3.8.2-16.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:gnutls-3.8.2-16.oe2403sp3.src",
						"openEuler-24.03-LTS-SP3:gnutls-3.8.2-16.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:gnutls-dane-3.8.2-16.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:gnutls-debuginfo-3.8.2-16.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:gnutls-debugsource-3.8.2-16.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:gnutls-devel-3.8.2-16.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:gnutls-utils-3.8.2-16.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:gnutls-help-3.8.2-16.oe2403sp3.noarch"
					]
				}
			],
			"threats":[
				{
					"details":"Low",
					"category":"impact"
				}
			],
			"title":"CVE-2026-3832"
		},
		{
			"cve":"CVE-2026-42012",
			"notes":[
				{
					"text":"A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP3:gnutls-3.8.2-16.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:gnutls-dane-3.8.2-16.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:gnutls-debuginfo-3.8.2-16.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:gnutls-debugsource-3.8.2-16.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:gnutls-devel-3.8.2-16.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:gnutls-utils-3.8.2-16.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:gnutls-3.8.2-16.oe2403sp3.src",
					"openEuler-24.03-LTS-SP3:gnutls-3.8.2-16.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:gnutls-dane-3.8.2-16.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:gnutls-debuginfo-3.8.2-16.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:gnutls-debugsource-3.8.2-16.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:gnutls-devel-3.8.2-16.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:gnutls-utils-3.8.2-16.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:gnutls-help-3.8.2-16.oe2403sp3.noarch"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP3:gnutls-3.8.2-16.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:gnutls-dane-3.8.2-16.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:gnutls-debuginfo-3.8.2-16.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:gnutls-debugsource-3.8.2-16.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:gnutls-devel-3.8.2-16.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:gnutls-utils-3.8.2-16.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:gnutls-3.8.2-16.oe2403sp3.src",
						"openEuler-24.03-LTS-SP3:gnutls-3.8.2-16.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:gnutls-dane-3.8.2-16.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:gnutls-debuginfo-3.8.2-16.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:gnutls-debugsource-3.8.2-16.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:gnutls-devel-3.8.2-16.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:gnutls-utils-3.8.2-16.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:gnutls-help-3.8.2-16.oe2403sp3.noarch"
					],
					"details":"gnutls security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3121"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":7.1,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP3:gnutls-3.8.2-16.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:gnutls-dane-3.8.2-16.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:gnutls-debuginfo-3.8.2-16.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:gnutls-debugsource-3.8.2-16.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:gnutls-devel-3.8.2-16.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:gnutls-utils-3.8.2-16.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:gnutls-3.8.2-16.oe2403sp3.src",
						"openEuler-24.03-LTS-SP3:gnutls-3.8.2-16.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:gnutls-dane-3.8.2-16.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:gnutls-debuginfo-3.8.2-16.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:gnutls-debugsource-3.8.2-16.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:gnutls-devel-3.8.2-16.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:gnutls-utils-3.8.2-16.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:gnutls-help-3.8.2-16.oe2403sp3.noarch"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-42012"
		}
	]
}