Bug 2456333 (CVE-2026-32281)

Summary: CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aazores, abarbaro, abrianik, akostadi, akoudelk, alcohan, alebedev, alizardo, amasferr, amctagga, anjoseph, anpicker, ansmith, anthomas, aoconnor, aruklets, asatyam, ataylor, bbrownin, bdettelb, bniver, bparees, chfoley, ckandaga, cmah, crizzo, csutherl, dakwon, dbruscin, dhanak, diagrawa, dkeler, dmayorov, doconnor, drosa, dschmidt, dsimansk, dsoumis, dymurray, eaguilar, ebaron, eborisov, eglynn, ehelms, ehugonne, erezende, ewittman, fdeutsch, flucifre, ggainey, ggrzybek, gmeno, gparvin, groman, hasun, ibolton, janstey, jbalunas, jbritton, jburrell, jcantril, jchui, jclere, jeder, jfula, jhe, jjoyce, jkoehler, jlanda, jlledo, jmatthew, jmontleo, jolong, jowilson, jpasqual, jprabhak, jpretori, jraez, jschluet, juwatts, jwon, kingland, kshier, ktsao, kvanderr, kverlaen, lball, lbragsta, lchilton, lgamliel, lhh, lphiri, manissin, mbenjamin, mbocek, mburns, mgarciac, mhackett, mhess, mhulan, mnovotny, mrunge, mwringe, nboldt, ngough, nipatil, nmoumoul, nyancey, oaljalju, ometelka, oramraz, osousa, pahickey, pantinor, parichar, pcreech, peholase, pgaikwad, pjindal, plodge, psrna, ptisnovs, pvasanth, rchan, rekumar, rfreiman, rgodfrey, rhaigner, rhel-process-autobot, rjohnson, rkubis, rmaucher, rojacob, sabiswas, sakbas, sausingh, sbratsla, sdawley, sfeifer, simaishi, slucidi, smallamp, smcdonal, smullick, sostapov, sseago, stcannon, stirabos, suppawar, swoodman, syedriko, szappis, tasato, teagle, thason, tmalecek, tsedmik, tzivkovi, vereddy, veshanka, vimartin, vkarehfa, vle, vvoronko, vwilson, watson-tool-maintainers, wenshen, whayutin, wtam, xdharmai, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Go's `crypto/x509` package. A remote attacker could exploit this by presenting a specially crafted certificate chain containing a large number of policy mappings. This inefficient validation process consumes excessive resources, which can lead to a denial of service (DoS) for applications or systems performing certificate validation.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2456732    
Bug Blocks:    

Description OSIDB Bzimport 2026-04-08 02:01:26 UTC
Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

Comment 7 errata-xmlrpc 2026-05-19 16:07:28 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:19135 https://access.redhat.com/errata/RHSA-2026:19135

Comment 8 errata-xmlrpc 2026-05-19 21:39:11 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:19353 https://access.redhat.com/errata/RHSA-2026:19353

Comment 12 errata-xmlrpc 2026-05-20 16:41:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:19719 https://access.redhat.com/errata/RHSA-2026:19719

Comment 13 errata-xmlrpc 2026-05-20 16:48:36 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2026:19721 https://access.redhat.com/errata/RHSA-2026:19721

Comment 14 errata-xmlrpc 2026-05-20 16:53:28 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:19720 https://access.redhat.com/errata/RHSA-2026:19720

Comment 15 errata-xmlrpc 2026-05-26 03:17:11 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:20570 https://access.redhat.com/errata/RHSA-2026:20570

Comment 16 errata-xmlrpc 2026-05-26 03:19:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:20569 https://access.redhat.com/errata/RHSA-2026:20569

Comment 17 errata-xmlrpc 2026-05-26 03:20:47 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:20571 https://access.redhat.com/errata/RHSA-2026:20571

Comment 19 errata-xmlrpc 2026-06-01 02:07:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:22141 https://access.redhat.com/errata/RHSA-2026:22141

Comment 20 errata-xmlrpc 2026-06-01 11:50:00 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:22309 https://access.redhat.com/errata/RHSA-2026:22309

Comment 29 errata-xmlrpc 2026-06-04 01:42:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:23103 https://access.redhat.com/errata/RHSA-2026:23103

Comment 30 errata-xmlrpc 2026-06-04 02:05:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:23102 https://access.redhat.com/errata/RHSA-2026:23102

Comment 31 errata-xmlrpc 2026-06-08 01:46:21 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:24337 https://access.redhat.com/errata/RHSA-2026:24337

Comment 32 errata-xmlrpc 2026-06-08 13:15:38 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:24470 https://access.redhat.com/errata/RHSA-2026:24470

Comment 33 errata-xmlrpc 2026-06-09 06:47:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:24716 https://access.redhat.com/errata/RHSA-2026:24716

Comment 34 errata-xmlrpc 2026-06-15 19:35:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:26054 https://access.redhat.com/errata/RHSA-2026:26054

Comment 35 errata-xmlrpc 2026-06-16 22:50:22 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:26447 https://access.redhat.com/errata/RHSA-2026:26447

Comment 36 errata-xmlrpc 2026-06-18 12:18:12 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.16 for RHEL 8
  Red Hat Satellite 6.16 for RHEL 9

Via RHSA-2026:27076 https://access.redhat.com/errata/RHSA-2026:27076

Comment 37 errata-xmlrpc 2026-06-22 01:57:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:27711 https://access.redhat.com/errata/RHSA-2026:27711

Comment 38 errata-xmlrpc 2026-06-22 03:58:41 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:27740 https://access.redhat.com/errata/RHSA-2026:27740

Comment 39 errata-xmlrpc 2026-06-22 17:15:31 UTC
This issue has been addressed in the following products:

  Cryostat 4 on RHEL 9

Via RHSA-2026:28010 https://access.redhat.com/errata/RHSA-2026:28010

Comment 40 errata-xmlrpc 2026-06-23 02:08:32 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:28074 https://access.redhat.com/errata/RHSA-2026:28074

Comment 41 errata-xmlrpc 2026-06-24 13:48:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:29035 https://access.redhat.com/errata/RHSA-2026:29035

Comment 42 errata-xmlrpc 2026-06-24 19:16:00 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:29195 https://access.redhat.com/errata/RHSA-2026:29195

Comment 43 errata-xmlrpc 2026-06-24 23:49:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:29455 https://access.redhat.com/errata/RHSA-2026:29455

Comment 44 errata-xmlrpc 2026-06-25 06:21:54 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:29702 https://access.redhat.com/errata/RHSA-2026:29702

Comment 45 errata-xmlrpc 2026-06-25 09:45:34 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:29703 https://access.redhat.com/errata/RHSA-2026:29703

Comment 46 errata-xmlrpc 2026-06-30 20:03:35 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:33722 https://access.redhat.com/errata/RHSA-2026:33722

Comment 47 errata-xmlrpc 2026-07-01 11:40:47 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:34192 https://access.redhat.com/errata/RHSA-2026:34192

Comment 48 errata-xmlrpc 2026-07-01 12:05:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:34197 https://access.redhat.com/errata/RHSA-2026:34197

Comment 49 errata-xmlrpc 2026-07-01 12:07:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:34196 https://access.redhat.com/errata/RHSA-2026:34196

Comment 50 errata-xmlrpc 2026-07-08 15:50:13 UTC
This issue has been addressed in the following products:

  RHEM 1.0 for RHEL 9

Via RHSA-2026:36796 https://access.redhat.com/errata/RHSA-2026:36796

Comment 51 errata-xmlrpc 2026-07-15 09:53:52 UTC
This issue has been addressed in the following products:

  Red Hat OpenStack Services on OpenShift 18.0

Via RHSA-2026:39810 https://access.redhat.com/errata/RHSA-2026:39810

Comment 52 Mirco Geremia 2026-07-15 14:13:36 UTC
Added rhem-1.1/flightctl affect and tracker. This stream was missing affects for this CVE since it went GA after the triage, but it's still vulnerable.

Comment 53 errata-xmlrpc 2026-07-16 14:31:27 UTC
This issue has been addressed in the following products:

  RHEM 1.1 for RHEL 10
  RHEM 1.1 for RHEL 9

Via RHSA-2026:41019 https://access.redhat.com/errata/RHSA-2026:41019

Comment 54 errata-xmlrpc 2026-07-20 15:58:13 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.5 for RHEL 9
  Red Hat Ansible Automation Platform 2.5 for RHEL 8

Via RHSA-2026:42078 https://access.redhat.com/errata/RHSA-2026:42078

Comment 55 errata-xmlrpc 2026-07-20 16:01:53 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.6 for RHEL 9
  Red Hat Ansible Automation Platform 2.6 for RHEL 10

Via RHSA-2026:42079 https://access.redhat.com/errata/RHSA-2026:42079

Comment 57 errata-xmlrpc 2026-07-29 21:11:33 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:47719 https://access.redhat.com/errata/RHSA-2026:47719

Comment 58 errata-xmlrpc 2026-07-29 21:44:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:47722 https://access.redhat.com/errata/RHSA-2026:47722

Comment 59 errata-xmlrpc 2026-07-29 21:46:13 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:47721 https://access.redhat.com/errata/RHSA-2026:47721

Comment 60 errata-xmlrpc 2026-07-29 22:02:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:47714 https://access.redhat.com/errata/RHSA-2026:47714

Comment 61 errata-xmlrpc 2026-07-29 22:04:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:47910 https://access.redhat.com/errata/RHSA-2026:47910

Comment 62 errata-xmlrpc 2026-07-29 22:14:34 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:47716 https://access.redhat.com/errata/RHSA-2026:47716

Comment 63 errata-xmlrpc 2026-07-29 22:19:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:47712 https://access.redhat.com/errata/RHSA-2026:47712

Comment 64 errata-xmlrpc 2026-07-29 22:41:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:48036 https://access.redhat.com/errata/RHSA-2026:48036

Comment 65 errata-xmlrpc 2026-08-03 02:00:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:49509 https://access.redhat.com/errata/RHSA-2026:49509

Comment 66 errata-xmlrpc 2026-08-03 04:20:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:49526 https://access.redhat.com/errata/RHSA-2026:49526

Comment 67 errata-xmlrpc 2026-08-03 06:29:36 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:49600 https://access.redhat.com/errata/RHSA-2026:49600

Comment 68 errata-xmlrpc 2026-08-04 02:14:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:49838 https://access.redhat.com/errata/RHSA-2026:49838

Comment 69 errata-xmlrpc 2026-08-04 10:00:20 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:49944 https://access.redhat.com/errata/RHSA-2026:49944

Comment 71 errata-xmlrpc 2026-08-06 20:28:45 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:51288 https://access.redhat.com/errata/RHSA-2026:51288

Comment 72 errata-xmlrpc 2026-08-13 23:39:01 UTC
This issue has been addressed in the following products:

  Red Hat OpenStack Platform 16.2

Via RHSA-2026:54757 https://access.redhat.com/errata/RHSA-2026:54757