CVE-2026-26994
MED 6.5uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for the handshake. In versions 1.6.7 and below, uTLS did not implement the TLS 1.3 downgrade protection mechanism specified in RFC 8446 Section 4.1.3 when using a uTLS ClientHello spec. This allowed an active network adversary to downgrade TLS 1.3 connections initiated by a uTLS client to a lower TLS version (e.g., TLS 1.2) by modifying the ClientHello message to exclude the SupportedVersions extension, causing the server to respond with a TLS 1.2 ServerHello (along with a downgrade canary in the ServerHello random field). Because uTLS did not check the downgrade canary in the ServerHello random field, clients would accept the downgraded connection without detecting the attack. This attack could also be used by an active network attacker to fingerprint uTLS connections. This issue has been fixed in version 1.7.0.
Affected Applications in Environment
14
gnutls
v3.6.16-8.el8_10.3
1 device
gnutls
v3.8.3-6.el9
20 devices
gnutls
v3.8.3-9.el9
5 devices
gnutls
v3.6.16-8.el8_10.4
4 devices
gnutls
v3.3.29-9.el7_6
1 device
gnutls
v3.8.3-10.el9_7
2 devices
gnutls
v3.8.3-6.el9_6.2
2 devices
gnutls
v3.8.3-10.el9_7
1 device
gnutls
v3.8.3-6.el9_6.2
1 device
gnutls
v3.6.16-6.el8_7
2 devices
gnutls
v3.6.16-8.el8_9.3
1 device
gnutls
v3.6.16-8.el8_10.3
1 device
gnutls
v3.8.10-3.el10_1
1 device
gnutls
v3.6.16-8.el8_10.4
2 devices
Affected Devices
44
atc.db.usu.edu
Linux
chela03
Linux
chela04
Linux
chela05
Linux
cleanaddressdev.banner.usu.edu
Linux
devjobsub.banner.usu.edu
Linux
dpapsb-161390.aggies.usu.edu
Linux
dpapsb-191594.mypc.usu.edu
Linux
el103-02.ece.usu.edu
Linux
el103-03.ece.usu.edu
Linux
el103-04.ece.usu.edu
Linux
el103-05.ece.usu.edu
Linux
el103-07.ece.usu.edu
Linux
el103-08.ece.usu.edu
Linux
el103-09.ece.usu.edu
Linux
el103-10.ece.usu.edu
Linux
el103-14.ece.usu.edu
Linux
el103-15.ece.usu.edu
Linux
el103-16.ece.usu.edu
Linux
el103-17.ece.usu.edu
Linux
el103-18.ece.usu.edu
Linux
el103-19.ece.usu.edu
Linux
el103-20.ece.usu.edu
Linux
el120-01.ece.usu.edu
Linux
el120-02.ece.usu.edu
Linux
el120-03.ece.usu.edu
Linux
el120-04.ece.usu.edu
Linux
el120-05.ece.usu.edu
Linux
el120-06.ece.usu.edu
Linux
el120-08.ece.usu.edu
Linux
el120-09.ece.usu.edu
Linux
el120-10.ece.usu.edu
Linux
el120-11.ece.usu.edu
Linux
el120-12.ece.usu.edu
Linux
el120-14.ece.usu.edu
Linux
eprocdev.banner.usu.edu
Linux
facreadyprod.pplant.usu.edu
Linux
facreadytestrhel.pplant.usu.edu
Linux
facshibsp2.pplant.usu.edu
Linux
guru.cluster
Linux
oms.db.usu.edu
Linux
paymentworksdev.banner.usu.edu
Linux
thinkstation
Linux
zldtst.db.usu.edu
Linux
References
4