Hello Wouter and Sam, Thanks a lot for reporting this, I'm just replying to say we're aware of the issue (thanks to the bug report) and we're still yet to perform a proper investigation and decide what to do next.
This seems to be the biggest threat to the GnuTLS switch so far. In the meantime, if any of you could provide an easy reproducer, it would save us a bit of time. Thank you! -- Samuel Henrique <samueloph>