Bug 2445345 (CVE-2026-27137)
| Summary: | CVE-2026-27137 crypto/x509: Incorrect enforcement of email constraints in crypto/x509 | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | aazores, abarbaro, abrianik, akostadi, akoudelk, alcohan, alebedev, alizardo, amasferr, anjoseph, anpicker, ansmith, anthomas, aruklets, bbrownin, bdettelb, chfoley, ckandaga, cmah, crizzo, dakwon, dhanak, dkeler, dmayorov, doconnor, drosa, dschmidt, dsimansk, dymurray, eaguilar, ebaron, eborisov, eglynn, ehelms, erezende, fdeutsch, ggainey, ggrzybek, gparvin, hasun, ibolton, jbalunas, jbritton, jburrell, jcantril, jchui, jeder, jfula, jhe, jjoyce, jkoehler, jlanda, jlledo, jmatthew, jmontleo, jolong, jowilson, jpasqual, jprabhak, jpretori, jraez, jschluet, juwatts, kingland, kshier, ktsao, kverlaen, lball, lbragsta, lchilton, lgamliel, lhh, lphiri, manissin, mbocek, mburns, mgarciac, mhulan, mnovotny, mrunge, mwringe, nboldt, ngough, nmoumoul, nyancey, oaljalju, ometelka, oramraz, osousa, pahickey, pantinor, parichar, pcreech, peholase, pgaikwad, pjindal, psrna, ptisnovs, pvasanth, rchan, rekumar, rfreiman, rgodfrey, rhaigner, rhel-process-autobot, rjohnson, rojacob, sakbas, sausingh, sbratsla, sdawley, sfeifer, simaishi, slucidi, smallamp, smcdonal, smullick, sseago, stcannon, stirabos, suppawar, swoodman, syedriko, tasato, teagle, thason, tmalecek, tsedmik, veshanka, vimartin, vvoronko, watson-tool-maintainers, wenshen, whayutin, wtam, xdharmai, yguenane |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A certificate validation flaw has been discovered in the golang crypto/x509 module. When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2446047 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-03-06 22:02:01 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:8842 https://access.redhat.com/errata/RHSA-2026:8842 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:10169 https://access.redhat.com/errata/RHSA-2026:10169 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:10929 https://access.redhat.com/errata/RHSA-2026:10929 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:19022 https://access.redhat.com/errata/RHSA-2026:19022 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:19049 https://access.redhat.com/errata/RHSA-2026:19049 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:19132 https://access.redhat.com/errata/RHSA-2026:19132 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:19181 https://access.redhat.com/errata/RHSA-2026:19181 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:22450 https://access.redhat.com/errata/RHSA-2026:22450 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:22714 https://access.redhat.com/errata/RHSA-2026:22714 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:22937 https://access.redhat.com/errata/RHSA-2026:22937 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:23228 https://access.redhat.com/errata/RHSA-2026:23228 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:28038 https://access.redhat.com/errata/RHSA-2026:28038 This issue has been addressed in the following products: RHEM 1.0 for RHEL 9 Via RHSA-2026:36796 https://access.redhat.com/errata/RHSA-2026:36796 This issue has been addressed in the following products: Red Hat OpenStack Services on OpenShift 18.0 Via RHSA-2026:39810 https://access.redhat.com/errata/RHSA-2026:39810 Added rhem-1.1/flightctl affect and tracker. This stream was missing affects for this CVE since it went GA after the triage, but it's still vulnerable. This issue has been addressed in the following products: RHEM 1.1 for RHEL 10 RHEM 1.1 for RHEL 9 Via RHSA-2026:41019 https://access.redhat.com/errata/RHSA-2026:41019 This issue has been addressed in the following products: Red Hat OpenStack Platform 16.2 Via RHSA-2026:54757 https://access.redhat.com/errata/RHSA-2026:54757 |