gnutls 3.8.12

Alexander Sosedkin <[email protected]> Mon, 9 Feb 2026 10:25:10 -0600
Newsgroups gmane.org.fsf.announce
Message-ID <CABMV8QNfycuBvhrHyKqP1D6XYe38v2DH_5iK-dvsa2Zav=Lp+Q__37587.6575986453$1770656177$gmane$org@mail.gmail.com>
--0000000000003cda4e064a6695fa
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hello,

We have just released gnutls-3.8.12. This is a bug fix, security and
enhancement release on the 3.8.x branch.

We would like to thank everyone who contributed in this release:
Alexander Sosedkin, Daiki Ueno, Mikhail Dmitrichenko, Franti=C5=A1ek Kren=
=C5=BEelok,
Jan Palus, Julien Olivain, Markus Theil, Maxim Cournoyer, xinpeng wang.

The detailed list of changes follows:

* Version 3.8.12 (released 2026-02-09)

** libgnutls: Fix NULL pointer dereference in PSK binder verification
   A TLS 1.3 resumption attempt with an invalid PSK binder value in ClientH=
ello
   could lead to a denial of service attack via crashing the server.
   The updated code guards against the problematic dereference.
   Reported by Jaehun Lee.
   [Fixes: GNUTLS-SA-2026-02-09-1, CVSS: high] [CVE-2026-1584]

** libgnutls: Fix name constraint processing performance issue
   Verifying certificates with pathological amounts of name constraints
   could lead to a denial of service attack via resource exhaustion.
   Reworked processing algorithms exhibit better performance characteristic=
s.
   Reported by Tim Scheckenbach.
   [Fixes: GNUTLS-SA-2026-02-09-2, CVSS: medium] [CVE-2025-14831]

** libgnutls: Fix multiple unexploitable overflows
   Reported by Tim R=C3=BChsen (#1783, #1786).

** libgnutls: Fall back to thread-unsafe module initialization
   Improve fallback handling for PKCS#11 modules that
   don't support thread-safe initialization (#1774).
   Also return filename from p11_kit_module_get_name() for unconfigured mod=
ules.

** libgnutls: Accept NULL as digest argument for gnutls_hash_output
   The accelerated implementation of gnutls_hash_output() now
   properly accepts NULL as the digest argument, matching the
   behavior of the reference implementation (#1769).

** srptool: Avoid a stack buffer overflow when processing large SRP groups.
   Reported and fixed by Mikhail Dmitrichenko (#1777).

** API and ABI modifications:
No changes since last version.


Getting the Software
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

GnuTLS may be downloaded directly from
https://www.gnupg.org/ftp/gcrypt/
A list of GnuTLS mirrors can be found at
http://www.gnutls.org/download.html

Here are the XZ compressed sources:
https://www.gnupg.org/ftp/gcrypt/gnutls/v3.8/gnutls-3.8.12.tar.xz

Here are OpenPGP detached signatures signed using keys:
5D46CB0F763405A7053556F47A75A648B3F9220C
and
E987AB7F7E89667776D05B3BB0E9DD20B29F1432
https://www.gnupg.org/ftp/gcrypt/gnutls/v3.8/gnutls-3.8.12.tar.xz.sig

Note that it has been signed with the following openpgp keys:

pub   ed25519 2021-12-23 [SC] [expires: 2027-01-01]
      5D46CB0F763405A7053556F47A75A648B3F9220C
uid           [ultimate] Zoltan Fridrich <[email protected]>
sub   cv25519 2021-12-23 [E] [expires: 2027-01-01]

pub   rsa4096 2016-09-27 [SC]
      E987AB7F7E89667776D05B3BB0E9DD20B29F1432
uid           [ultimate] Alexander Sosedkin <[email protected]>
sub   rsa4096 2021-08-21 [A]
sub   rsa4096 2016-09-27 [E]
sub   rsa4096 2016-09-27 [S]


Regards,
Alexander Sosedkin

--0000000000003cda4e064a6695fa
Content-Type: application/pgp-signature; name="signature.asc"; charset="us-ascii"
Content-Disposition: attachment; filename="signature.asc"
Content-Transfer-Encoding: base64
X-Attachment-Id: 268584b8fdacf951_0.1

LS0tLS1CRUdJTiBQR1AgU0lHTkFUVVJFLS0tLS0NCg0KaVFJekJBQUJDZ0FkRmlFRXBxdFRvQjBq
ZXBUNTdzVFFRU2RJcEFyOHd2c0ZBbW1LQ2x3QUNna1FRU2RJcEFyOA0Kd3Z0cFR3Ly9lWkhPZ3Vp
SWVMOEVLR0lKb0Rwa0xHOU9NUEI3aHI5SEE2STIwV05QL2ozSGNkUVJVMmlMOGUwcg0KSS9pRUxG
NXNseTFEM1dmK09yWlQyeUU0VG9lbHlYT1RjTUhUMXM4Qm9EdVMzZ3VRa2VXR2I5U2RJYSthWGVK
bQ0KMWIxOXkzbVIvdmx3ZkV0WFAwUmJDb1FnSndVOW42em5vUzNsTGh1MGVzUkVWYUxISm12Z3lB
czVnaHRPSTRGWQ0KdlllVTRGbnpLclFEcWdNSVVhYmt1YU1BR2lmM0twL25FSWcxQWEraGN1Tkh0
RVlHV3hUVDBPd2ltNytaMWxSbg0KaHhhc1Q0dGdqajhlUlpVL3dCTnVwUCthTmxVNStRUnhWcGdO
SStmcWZlemoyQkVkNzZoMUxQOEhQamRTV3VBOQ0KbWdoSjd5eDIxd3ZveEdOV0xjOHE4dUFTd1pr
UGxnQTRQMHhPeFY1LzhNY1QyMENzUk40U0pCYjlnSEVTenNNZg0KWmlOc1cwcVpJVEpsNG5PZDB1
aEsrblBlMlQzaFh1NXB6NmFMK0o1Z3hLbmJ6TFRxY216Ry9WeSs4QnQzUnBldw0Ka2V4aUpYNEt3
MDZrTGx2WUJxV3hSV3hWSm9rbnpOd2NzWHd4dU10MGs1Sy9EMEtkWFFCY0J6c3dQNUJ1eHR0UA0K
WXBwVEpQdlJyK1NYb0JZVlZtWllZcFpIMWVYOEk2bXNiZStaWjluaHpCekk4UHhRMXV5MngrSWk0
S2hnQWZXOA0KeW9CNllsa1JDTmN4MU9yRjVBYjRlK1B1ZzBqd3NNMXpaa2Qza2VxNjZjZWJ1NHE3
OGRnSVJ1N2dUUWFxbXJCeA0Kak5PZDlXQmFDWVFXNmpIVDNhN0xXZkFweCtFUTh0OElmT1pIM2Qw
Y2F1SUlTbjBhRVU0PQ0KPTIvWUoNCi0tLS0tRU5EIFBHUCBTSUdOQVRVUkUtLS0tLQ0K
--0000000000003cda4e064a6695fa--