CVE-2024-0567 - CVE House
Back to Database
Status published High CVE-2024-0567

Gnutls: rejects certificate chain with distributed trust

Vulnerability Description

A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-0567

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.2 Extended Update Support, RHODF-4.15-RHEL-9, RHOL-5.8-RHEL-9, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat OpenShift Container Platform 3.11
Vulnerable Versions:
3.8.0, 0:3.7.6-23.el9_3.3, 0:3.7.6-21.el9_2.2, v4.15.0-37, v4.15.0-68, v4.15.0-158, v4.15.0-39, v4.15.0-58, v4.15.0-13, v4.15.0-81, v4.15.0-79, v4.15.0-22, v4.15.0-57, v4.15.0-6, v4.15.0-15, v4.15.0-54, v4.15.0-10, v4.15.0-26, v4.15.0-19, v4.15.0-21, v4.15.0-103, v5.8.6-22, v5.8.6-11, v6.8.1-407, v5.8.6-19, v1.0.0-479, v5.8.6-7, v0.4.0-247, v5.8.6-5, v1.1.0-227, v5.8.1-470, v2.9.6-14, v5.8.6-2, v5.8.6-24, v5.8.6-10, v0.1.0-525, v0.1.0-224, v0.28.1-56

Timeline

Official Publish: January 16th, 2024
Last Modified: November 20th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)