Bug 2467437 (CVE-2026-42011)

Summary: CVE-2026-42011 gnutls: gnutls: Security bypass due to incorrect name constraint handling
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: kshier, rhel-process-autobot, stcannon, teagle, watson-tool-maintainers, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-05-06 19:07:55 UTC
libgnutls: Fix intersecting empty constraints
   Permitted name constraints were wrongfully ignored
   when prior CAs only had excluded name constraints,
   resulting in a name constraint bypass.
   Reported by .

Comment 2 errata-xmlrpc 2026-05-26 06:15:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:20611 https://access.redhat.com/errata/RHSA-2026:20611

Comment 3 errata-xmlrpc 2026-05-26 06:18:00 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:20613 https://access.redhat.com/errata/RHSA-2026:20613

Comment 4 errata-xmlrpc 2026-05-26 06:20:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:20612 https://access.redhat.com/errata/RHSA-2026:20612

Comment 10 errata-xmlrpc 2026-06-16 16:39:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:26409 https://access.redhat.com/errata/RHSA-2026:26409

Comment 12 errata-xmlrpc 2026-06-25 18:07:35 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:30004 https://access.redhat.com/errata/RHSA-2026:30004

Comment 13 errata-xmlrpc 2026-06-29 02:30:16 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:30850 https://access.redhat.com/errata/RHSA-2026:30850

Comment 14 errata-xmlrpc 2026-06-29 02:48:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:30849 https://access.redhat.com/errata/RHSA-2026:30849

Comment 15 errata-xmlrpc 2026-06-29 09:47:22 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:32962 https://access.redhat.com/errata/RHSA-2026:32962

Comment 16 errata-xmlrpc 2026-06-29 15:07:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:33125 https://access.redhat.com/errata/RHSA-2026:33125