libgnutls: Servers configured with RSA-PSK have wrongfully matched usernames with NUL character in them to ones truncated to NUL character, which could lead to an authentication bypass. Fix the check to perform comparison up to the full username length. Reported by Joshua Rogers of AISLE Research Team. [GNUTLS-SA-2026-04-29-4, CVSS: high] [CVE-2026-42010]
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:20611 https://access.redhat.com/errata/RHSA-2026:20611
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:20613 https://access.redhat.com/errata/RHSA-2026:20613
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:20612 https://access.redhat.com/errata/RHSA-2026:20612
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:26409 https://access.redhat.com/errata/RHSA-2026:26409