Bug 2484207 (CVE-2026-27145)
| Summary: | CVE-2026-27145 crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | aazores, abarbaro, akhatavk, akostadi, akoudelk, alcohan, alebedev, alizardo, amasferr, amctagga, anjoseph, anpicker, ansmith, anthomas, aoconnor, aos-team-art-private, aprice, aruklets, asatyam, asdas, bbrownin, bdettelb, bniver, chfoley, ckandaga, cmah, crizzo, dakwon, dhanak, diagrawa, dkeler, dmayorov, doconnor, dpaolell, drosa, dschmidt, dsimansk, dymurray, eaguilar, ebaron, eborisov, eglynn, ehelms, erezende, ewittman, fdeutsch, flucifre, gbenhaim, ggainey, gmeno, gparvin, groman, hasun, ibolton, jaharrin, janstey, jbalunas, jbritton, jburrell, jcantril, jchui, jdelft, jeder, jfula, jhe, jjoyce, jkoehler, jlanda, jlledo, jmatsuok, jmatthew, jmontleo, jolong, jowilson, jpasqual, jprabhak, jpretori, jsamir, jschluet, jtolenti, jturenov, jupierce, juwatts, kaycoth, kingland, kshier, ktsao, kverlaen, lball, lbragsta, lchilton, lgamliel, lgarciaa, lhh, lphiri, lwan, manissin, mbenjamin, mbiarnes, mbocek, mburns, mdellweg, mgarciac, mhackett, mhess, mhulan, mnovotny, mrunge, mwringe, nboldt, ngough, nipatil, niyer, nmoumoul, nyancey, oaljalju, oezr, ometelka, oramraz, osousa, pahickey, pantinor, pcreech, peholase, pgaikwad, pjindal, ppalepu, ppostler, prdhamdh, psrna, ptisnovs, pvasanth, rchan, rekumar, rfreiman, rgodfrey, rhaigner, rhel-process-autobot, rjohnson, rkubis, rojacob, sabiswas, sakbas, sausingh, sbratsla, sdawley, sfeifer, sghai, sidsharm, simaishi, slucidi, smallamp, smcdonal, smullick, sostapov, sseago, stcannon, stirabos, suppawar, swoodman, syedriko, teagle, thason, tmalecek, tsedmik, tsze, twaugh, tzivkovi, vereddy, veshanka, vimartin, vkarehfa, vlaad, vle, vvoronko, vwilson, watson-tool-maintainers, wenshen, whayutin, wtam, xdharmai, xiyuan, yguenane |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the `crypto/x509` package of `golang`. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by presenting a specially crafted X.509 certificate with a large number of DNS Subject Alternative Name (SAN) entries. The certificate verification process, specifically the `VerifyHostname` function, incurs excessive computational overhead due to repeated string operations when processing these entries. This can lead to a significant performance degradation or unresponsiveness of systems validating such certificates.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2494206, 2494207, 2494210, 2494211, 2494212, 2494213, 2494215, 2494217, 2494218, 2494219, 2494221, 2494222, 2494223, 2494224, 2494226, 2494227, 2494228, 2494229, 2494230, 2494231, 2494232, 2494233, 2494235, 2494236, 2494240, 2494241, 2494242, 2494243, 2494244, 2494245, 2494247, 2494248, 2494250, 2494251, 2494252, 2494253, 2494254, 2494255, 2494256, 2494257, 2494258, 2494259, 2494260, 2494261, 2494262, 2494263, 2494265, 2494266, 2494269, 2494270, 2494271, 2494273, 2494275, 2494276, 2494277, 2494278, 2494279, 2494280, 2494284, 2494285, 2494287, 2494289, 2494290, 2494291, 2494292, 2494293, 2494294, 2494297, 2494300, 2494301, 2494302, 2494304, 2494306, 2494307, 2494308, 2494312, 2494313, 2494314, 2494315, 2494317, 2494318, 2494319, 2494320, 2494321, 2494323, 2494325, 2494327, 2494329, 2494330, 2494332, 2494335, 2494336, 2494337, 2494338, 2494339, 2494340, 2494341, 2494343, 2494344, 2494346, 2494347, 2494348, 2494349, 2494350, 2494354, 2494355, 2494356, 2494357, 2494358, 2494360, 2494361, 2494362, 2494363, 2494366, 2494367, 2494368, 2494369, 2494370, 2494371, 2494372, 2494373, 2494374, 2494376, 2494377, 2494378, 2494379, 2494380, 2494381, 2494382, 2494384, 2494385, 2494386, 2494387, 2494390, 2494392, 2494393, 2494395, 2494396, 2494397, 2494398, 2494399, 2494403, 2494404, 2494405, 2494406, 2494407, 2494408, 2494409, 2494418, 2494205, 2494208, 2494209, 2494214, 2494216, 2494220, 2494225, 2494234, 2494238, 2494239, 2494246, 2494249, 2494264, 2494267, 2494272, 2494281, 2494282, 2494283, 2494295, 2494296, 2494298, 2494299, 2494309, 2494310, 2494311, 2494316, 2494322, 2494324, 2494326, 2494331, 2494333, 2494334, 2494342, 2494345, 2494359, 2494364, 2494365, 2494375, 2494383, 2494388, 2494389, 2494391, 2494394, 2494400, 2494401, 2494402 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-06-02 23:01:31 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:34357 https://access.redhat.com/errata/RHSA-2026:34357 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:34359 https://access.redhat.com/errata/RHSA-2026:34359 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:35832 https://access.redhat.com/errata/RHSA-2026:35832 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:36317 https://access.redhat.com/errata/RHSA-2026:36317 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:38995 https://access.redhat.com/errata/RHSA-2026:38995 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:39005 https://access.redhat.com/errata/RHSA-2026:39005 FEDORA-2026-d7dfd8e9ba (golang-github-openprinting-ipp-usb-0.9.34-1.fc43) has been pushed to the Fedora 43 stable repository. If problem still persists, please make note of it in this bug report. This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:39573 https://access.redhat.com/errata/RHSA-2026:39573 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:39879 https://access.redhat.com/errata/RHSA-2026:39879 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:41930 https://access.redhat.com/errata/RHSA-2026:41930 This issue has been addressed in the following products: Red Hat Ansible Automation Platform 2.7 for RHEL 9 Red Hat Ansible Automation Platform 2.7 for RHEL 10 Via RHSA-2026:42080 https://access.redhat.com/errata/RHSA-2026:42080 This issue has been addressed in the following products: Red Hat Satellite 6.16 for RHEL 8 Red Hat Satellite 6.16 for RHEL 9 Via RHSA-2026:42082 https://access.redhat.com/errata/RHSA-2026:42082 This issue has been addressed in the following products: Red Hat Ansible Automation Platform 2.6 for RHEL 9 Red Hat Ansible Automation Platform 2.6 for RHEL 10 Via RHSA-2026:42079 https://access.redhat.com/errata/RHSA-2026:42079 This issue has been addressed in the following products: Red Hat Satellite 6.17 for RHEL 9 Via RHSA-2026:42150 https://access.redhat.com/errata/RHSA-2026:42150 This issue has been addressed in the following products: Red Hat Satellite 6.18 for RHEL 9 Via RHSA-2026:42151 https://access.redhat.com/errata/RHSA-2026:42151 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:42946 https://access.redhat.com/errata/RHSA-2026:42946 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:46394 https://access.redhat.com/errata/RHSA-2026:46394 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:46395 https://access.redhat.com/errata/RHSA-2026:46395 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:49702 https://access.redhat.com/errata/RHSA-2026:49702 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:49703 https://access.redhat.com/errata/RHSA-2026:49703 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:49712 https://access.redhat.com/errata/RHSA-2026:49712 This issue has been addressed in the following products: Red Hat Ansible Automation Platform 2.5 for RHEL 9 Red Hat Ansible Automation Platform 2.5 for RHEL 8 Via RHSA-2026:50319 https://access.redhat.com/errata/RHSA-2026:50319 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:51187 https://access.redhat.com/errata/RHSA-2026:51187 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:53374 https://access.redhat.com/errata/RHSA-2026:53374 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:53413 https://access.redhat.com/errata/RHSA-2026:53413 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:53412 https://access.redhat.com/errata/RHSA-2026:53412 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:53416 https://access.redhat.com/errata/RHSA-2026:53416 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:53415 https://access.redhat.com/errata/RHSA-2026:53415 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:54168 https://access.redhat.com/errata/RHSA-2026:54168 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:54401 https://access.redhat.com/errata/RHSA-2026:54401 This issue has been addressed in the following products: Red Hat OpenStack Platform 16.2 Via RHSA-2026:54757 https://access.redhat.com/errata/RHSA-2026:54757 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:57649 https://access.redhat.com/errata/RHSA-2026:57649 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:60315 https://access.redhat.com/errata/RHSA-2026:60315 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.18 Via RHSA-2026:57482 https://access.redhat.com/errata/RHSA-2026:57482 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:60354 https://access.redhat.com/errata/RHSA-2026:60354 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:61253 https://access.redhat.com/errata/RHSA-2026:61253 This issue has been addressed in the following products: RHEM 1.2 for RHEL 10 RHEM 1.2 for RHEL 9 Via RHSA-2026:68335 https://access.redhat.com/errata/RHSA-2026:68335 This issue has been addressed in the following products: RHEM 1.1 for RHEL 10 RHEM 1.1 for RHEL 9 Via RHSA-2026:68334 https://access.redhat.com/errata/RHSA-2026:68334 |