Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-0553

23
FAUCET Score

CVE-2024-0553 is a timing side-channel vulnerability in GnuTLS affecting various Fedora and Red Hat Enterprise Linux products. It allows a remote attacker to differentiate response times to malformed RSA-PSK ClientKeyExchange ciphertexts, potentially leading to sensitive data leakage. Rated 7.5 HIGH on CVSS, this vulnerability has a low attack complexity and requires no user interaction. There is currently no known active exploitation, public exploit code, or significant community discussion surrounding this issue.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.8.3CPE matchmatch criteria
cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:*
39CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.61%
Probability of exploitation in next 30 days
EPSS Percentile
73.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0161 is in the 56th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (61)

denopatch availablevia llm_extracted
View patch
keraspatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: 17380-16823Fixed in: 3.7.11-1
microsoftpatch availablevia msrc
Product: 17820-17084Fixed in: 3.8.3-1
microsoftpatch availablevia msrc
Product: 20076-17084Fixed in: 3.8.3-1
microsoftpatch availablevia msrc
Product: azl3 gnutls 3.8.2-1 on Azure Linux 3.0Fixed in: 3.8.3-1
microsoftpatch availablevia msrc
Product: azl3 gnutls 3.8.3-1 on Azure Linux 3.0Fixed in: 3.8.3-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 3.8.3-1
microsoftpatch availablevia msrc
Product: cbl2 gnutls 3.7.11-1 on CBL Mariner 2.0Fixed in: 3.7.11-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 3.8.3-1
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/ocs-client-operator-bundle:v4.15.0-158
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/ocs-client-rhel9-operator:v4.15.0-13
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/ocs-metrics-exporter-rhel9:v4.15.0-81
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/ocs-operator-bundle:v4.15.0-158
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/ocs-rhel9-operator:v4.15.0-79
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/odf-cli-rhel9:v4.15.0-22
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/odf-console-rhel9:v4.15.0-57
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/odf-cosi-sidecar-rhel9:v4.15.0-6
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/odf-csi-addons-operator-bundle:v4.15.0-158
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/odf-csi-addons-rhel9-operator:v4.15.0-15
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/odf-csi-addons-sidecar-rhel9:v4.15.0-15
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/odf-multicluster-console-rhel9:v4.15.0-54
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/odf-multicluster-operator-bundle:v4.15.0-158
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/odf-multicluster-rhel9-operator:v4.15.0-10
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/odf-must-gather-rhel9:v4.15.0-26
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/odf-operator-bundle:v4.15.0-158
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/odf-rhel9-operator:v4.15.0-19
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/odr-cluster-operator-bundle:v4.15.0-158
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/odr-hub-operator-bundle:v4.15.0-158
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/odr-rhel9-operator:v4.15.0-21
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/rook-ceph-rhel9-operator:v4.15.0-103
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/cluster-logging-operator-bundle:v5.8.6-22
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/cluster-logging-rhel9-operator:v5.8.6-11
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/elasticsearch6-rhel9:v6.8.1-407
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/elasticsearch-operator-bundle:v5.8.6-19
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/elasticsearch-proxy-rhel9:v1.0.0-479
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/elasticsearch-rhel9-operator:v5.8.6-7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gnutls-0:3.6.16-8.el8_9.1
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/fluentd-rhel9:v5.8.6-5
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/log-file-metric-exporter-rhel9:v1.1.0-227
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/logging-curator5-rhel9:v5.8.1-470
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/logging-loki-rhel9:v2.9.6-14
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/logging-view-plugin-rhel9:v5.8.6-2
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/loki-operator-bundle:v5.8.6-24
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/loki-rhel9-operator:v5.8.6-10
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/lokistack-gateway-rhel9:v0.1.0-525
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/opa-openshift-rhel9:v0.1.0-224
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/vector-rhel9:v0.28.1-56
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/eventrouter-rhel9:v0.4.0-247
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: gnutls-0:3.6.16-5.el8_6.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: gnutls-0:3.6.16-7.el8_8.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: gnutls-0:3.7.6-23.el9_3.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: gnutls-0:3.7.6-21.el9_2.2
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/cephcsi-rhel9:v4.15.0-37
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/mcg-core-rhel9:v4.15.0-68
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/mcg-operator-bundle:v4.15.0-158
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/mcg-rhel9-operator:v4.15.0-39
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/ocs-client-console-rhel9:v4.15.0-58
View patch
ubuntupatch availablevia ubuntu_usn
Product: gnutls28 (xenial)Fixed in: 3.4.10-4ubuntu1.9+esm3
ubuntupatch availablevia ubuntu_usn
Product: gnutls28 (focal)Fixed in: 3.6.13-2ubuntu1.12+esm2
ubuntupatch availablevia ubuntu_usn
Product: gnutls28 (bionic)Fixed in: 3.5.18-1ubuntu1.6+esm3

Vendor Advisories (6)

ubuntuUSN-8502-1

GnuTLS vulnerabilities

Jul 6, 2026
denollm-deno-b67a3af2ce0be075CRITICAL

HP ThinPro 8.0 SP 9 Security Updates

Jun 17, 2024
kerasllm-keras-7d8c31fee70361dcCRITICAL

HP ThinPro 8.0 SP 9 Security Updates

Jun 17, 2024
microsoft2024-Jun/CVE-2024-0553

CVE-2024-0553

Jun 11, 2024
redhatCVE-2024-0553Moderate

gnutls: incomplete fix for CVE-2023-5981

Jan 16, 2024
microsoft2024-Jan/CVE-2024-0553Important

Gnutls: incomplete fix for cve-2023-5981

Jan 9, 2024

References

lists.debian.org / debian-lts-announce/2024/02/msg00010.html
lists.fedoraproject.org / archives/list/[email protected]/message/7ZEIOLORQ7N6WRPFXZSYDL2MC4LP7VFV
lists.fedoraproject.org / archives/list/[email protected]/message/GNXKVR5YNUEBNHAHM5GSYKBZX4W2HMN2
security.netapp.com / advisory/ntap-20240202-0011
openwall.com / lists/oss-security/2024/01/19/3
access.redhat.com / errata/RHSA-2024:0533
access.redhat.com / errata/RHSA-2024:0627
access.redhat.com / errata/RHSA-2024:0796
access.redhat.com / errata/RHSA-2024:1082
access.redhat.com / errata/RHSA-2024:1108
access.redhat.com / errata/RHSA-2024:1383
access.redhat.com / errata/RHSA-2024:2094
access.redhat.com / security/cve/CVE-2024-0553
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
gitlab.com / gnutls/gnutls/-/issues/1522
ExploitIssue TrackingVendor Advisory
lists.gnupg.org / pipermail/gnutls-help/2024-January/004841.html
Mailing List