Bug 2484207 (CVE-2026-27145)

Summary: CVE-2026-27145 crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: aazores, abarbaro, akhatavk, akostadi, akoudelk, alcohan, alebedev, alizardo, amasferr, amctagga, anjoseph, anpicker, ansmith, anthomas, aoconnor, aos-team-art-private, aprice, aruklets, asatyam, asdas, bbrownin, bdettelb, bniver, chfoley, ckandaga, cmah, crizzo, dakwon, dhanak, diagrawa, dkeler, dmayorov, doconnor, dpaolell, drosa, dschmidt, dsimansk, dymurray, eaguilar, ebaron, eborisov, eglynn, ehelms, erezende, ewittman, fdeutsch, flucifre, gbenhaim, ggainey, gmeno, gparvin, groman, hasun, ibolton, jaharrin, janstey, jbalunas, jbritton, jburrell, jcantril, jchui, jdelft, jeder, jfula, jhe, jjoyce, jkoehler, jlanda, jlledo, jmatsuok, jmatthew, jmontleo, jolong, jowilson, jpasqual, jprabhak, jpretori, jsamir, jschluet, jtolenti, jturenov, jupierce, juwatts, kaycoth, kingland, kshier, ktsao, kverlaen, lball, lbragsta, lchilton, lgamliel, lgarciaa, lhh, lphiri, lwan, manissin, mbenjamin, mbiarnes, mbocek, mburns, mdellweg, mgarciac, mhackett, mhess, mhulan, mnovotny, mrunge, mwringe, nboldt, ngough, nipatil, niyer, nmoumoul, nyancey, oaljalju, oezr, ometelka, oramraz, osousa, pahickey, pantinor, pcreech, peholase, pgaikwad, pjindal, ppalepu, ppostler, prdhamdh, psrna, ptisnovs, pvasanth, rchan, rekumar, rfreiman, rgodfrey, rhaigner, rhel-process-autobot, rjohnson, rkubis, rojacob, sabiswas, sakbas, sausingh, sbratsla, sdawley, sfeifer, sghai, sidsharm, simaishi, slucidi, smallamp, smcdonal, smullick, sostapov, sseago, stcannon, stirabos, suppawar, swoodman, syedriko, teagle, thason, tmalecek, tsedmik, tsze, twaugh, tzivkovi, vereddy, veshanka, vimartin, vkarehfa, vlaad, vle, vvoronko, vwilson, watson-tool-maintainers, wenshen, whayutin, wtam, xdharmai, xiyuan, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the `crypto/x509` package of `golang`. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by presenting a specially crafted X.509 certificate with a large number of DNS Subject Alternative Name (SAN) entries. The certificate verification process, specifically the `VerifyHostname` function, incurs excessive computational overhead due to repeated string operations when processing these entries. This can lead to a significant performance degradation or unresponsiveness of systems validating such certificates.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2494206, 2494207, 2494210, 2494211, 2494212, 2494213, 2494215, 2494217, 2494218, 2494219, 2494221, 2494222, 2494223, 2494224, 2494226, 2494227, 2494228, 2494229, 2494230, 2494231, 2494232, 2494233, 2494235, 2494236, 2494240, 2494241, 2494242, 2494243, 2494244, 2494245, 2494247, 2494248, 2494250, 2494251, 2494252, 2494253, 2494254, 2494255, 2494256, 2494257, 2494258, 2494259, 2494260, 2494261, 2494262, 2494263, 2494265, 2494266, 2494269, 2494270, 2494271, 2494273, 2494275, 2494276, 2494277, 2494278, 2494279, 2494280, 2494284, 2494285, 2494287, 2494289, 2494290, 2494291, 2494292, 2494293, 2494294, 2494297, 2494300, 2494301, 2494302, 2494304, 2494306, 2494307, 2494308, 2494312, 2494313, 2494314, 2494315, 2494317, 2494318, 2494319, 2494320, 2494321, 2494323, 2494325, 2494327, 2494329, 2494330, 2494332, 2494335, 2494336, 2494337, 2494338, 2494339, 2494340, 2494341, 2494343, 2494344, 2494346, 2494347, 2494348, 2494349, 2494350, 2494354, 2494355, 2494356, 2494357, 2494358, 2494360, 2494361, 2494362, 2494363, 2494366, 2494367, 2494368, 2494369, 2494370, 2494371, 2494372, 2494373, 2494374, 2494376, 2494377, 2494378, 2494379, 2494380, 2494381, 2494382, 2494384, 2494385, 2494386, 2494387, 2494390, 2494392, 2494393, 2494395, 2494396, 2494397, 2494398, 2494399, 2494403, 2494404, 2494405, 2494406, 2494407, 2494408, 2494409, 2494418, 2494205, 2494208, 2494209, 2494214, 2494216, 2494220, 2494225, 2494234, 2494238, 2494239, 2494246, 2494249, 2494264, 2494267, 2494272, 2494281, 2494282, 2494283, 2494295, 2494296, 2494298, 2494299, 2494309, 2494310, 2494311, 2494316, 2494322, 2494324, 2494326, 2494331, 2494333, 2494334, 2494342, 2494345, 2494359, 2494364, 2494365, 2494375, 2494383, 2494388, 2494389, 2494391, 2494394, 2494400, 2494401, 2494402    
Bug Blocks:    

Description OSIDB Bzimport 2026-06-02 23:01:31 UTC
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

Comment 11 errata-xmlrpc 2026-07-01 18:36:23 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:34357 https://access.redhat.com/errata/RHSA-2026:34357

Comment 12 errata-xmlrpc 2026-07-01 19:21:18 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:34359 https://access.redhat.com/errata/RHSA-2026:34359

Comment 13 errata-xmlrpc 2026-07-06 03:05:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:35832 https://access.redhat.com/errata/RHSA-2026:35832

Comment 16 errata-xmlrpc 2026-07-07 17:56:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:36317 https://access.redhat.com/errata/RHSA-2026:36317

Comment 20 errata-xmlrpc 2026-07-13 14:12:34 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:38995 https://access.redhat.com/errata/RHSA-2026:38995

Comment 21 errata-xmlrpc 2026-07-13 16:00:11 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:39005 https://access.redhat.com/errata/RHSA-2026:39005

Comment 22 Fedora Update System 2026-07-14 01:23:32 UTC
FEDORA-2026-d7dfd8e9ba (golang-github-openprinting-ipp-usb-0.9.34-1.fc43) has been pushed to the Fedora 43 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 24 errata-xmlrpc 2026-07-15 00:43:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:39573 https://access.redhat.com/errata/RHSA-2026:39573

Comment 25 errata-xmlrpc 2026-07-15 12:08:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:39879 https://access.redhat.com/errata/RHSA-2026:39879

Comment 27 errata-xmlrpc 2026-07-20 11:17:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:41930 https://access.redhat.com/errata/RHSA-2026:41930

Comment 28 errata-xmlrpc 2026-07-20 15:53:27 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.7 for RHEL 9
  Red Hat Ansible Automation Platform 2.7 for RHEL 10

Via RHSA-2026:42080 https://access.redhat.com/errata/RHSA-2026:42080

Comment 29 errata-xmlrpc 2026-07-20 16:01:08 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.16 for RHEL 8
  Red Hat Satellite 6.16 for RHEL 9

Via RHSA-2026:42082 https://access.redhat.com/errata/RHSA-2026:42082

Comment 30 errata-xmlrpc 2026-07-20 16:02:33 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.6 for RHEL 9
  Red Hat Ansible Automation Platform 2.6 for RHEL 10

Via RHSA-2026:42079 https://access.redhat.com/errata/RHSA-2026:42079

Comment 31 errata-xmlrpc 2026-07-20 19:29:20 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.17 for RHEL 9

Via RHSA-2026:42150 https://access.redhat.com/errata/RHSA-2026:42150

Comment 32 errata-xmlrpc 2026-07-20 19:29:39 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.18 for RHEL 9

Via RHSA-2026:42151 https://access.redhat.com/errata/RHSA-2026:42151

Comment 33 errata-xmlrpc 2026-07-21 19:59:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:42946 https://access.redhat.com/errata/RHSA-2026:42946

Comment 34 errata-xmlrpc 2026-07-27 02:29:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:46394 https://access.redhat.com/errata/RHSA-2026:46394

Comment 35 errata-xmlrpc 2026-07-27 02:32:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:46395 https://access.redhat.com/errata/RHSA-2026:46395

Comment 37 errata-xmlrpc 2026-08-03 15:59:50 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:49702 https://access.redhat.com/errata/RHSA-2026:49702

Comment 38 errata-xmlrpc 2026-08-03 16:11:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:49703 https://access.redhat.com/errata/RHSA-2026:49703

Comment 39 errata-xmlrpc 2026-08-03 17:34:29 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:49712 https://access.redhat.com/errata/RHSA-2026:49712

Comment 40 errata-xmlrpc 2026-08-04 17:57:35 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.5 for RHEL 9
  Red Hat Ansible Automation Platform 2.5 for RHEL 8

Via RHSA-2026:50319 https://access.redhat.com/errata/RHSA-2026:50319

Comment 41 errata-xmlrpc 2026-08-06 18:15:38 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:51187 https://access.redhat.com/errata/RHSA-2026:51187

Comment 42 errata-xmlrpc 2026-08-11 09:57:47 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:53374 https://access.redhat.com/errata/RHSA-2026:53374

Comment 43 errata-xmlrpc 2026-08-11 11:35:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:53413 https://access.redhat.com/errata/RHSA-2026:53413

Comment 44 errata-xmlrpc 2026-08-11 12:05:13 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:53412 https://access.redhat.com/errata/RHSA-2026:53412

Comment 45 errata-xmlrpc 2026-08-11 12:05:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2026:53416 https://access.redhat.com/errata/RHSA-2026:53416

Comment 46 errata-xmlrpc 2026-08-11 12:07:21 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:53415 https://access.redhat.com/errata/RHSA-2026:53415

Comment 47 errata-xmlrpc 2026-08-12 05:26:14 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:54168 https://access.redhat.com/errata/RHSA-2026:54168

Comment 48 errata-xmlrpc 2026-08-12 15:49:01 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:54401 https://access.redhat.com/errata/RHSA-2026:54401

Comment 49 errata-xmlrpc 2026-08-13 23:38:18 UTC
This issue has been addressed in the following products:

  Red Hat OpenStack Platform 16.2

Via RHSA-2026:54757 https://access.redhat.com/errata/RHSA-2026:54757

Comment 51 errata-xmlrpc 2026-08-20 18:47:37 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:57649 https://access.redhat.com/errata/RHSA-2026:57649

Comment 52 errata-xmlrpc 2026-08-26 13:54:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:60315 https://access.redhat.com/errata/RHSA-2026:60315

Comment 53 errata-xmlrpc 2026-08-26 15:16:24 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.18

Via RHSA-2026:57482 https://access.redhat.com/errata/RHSA-2026:57482

Comment 54 errata-xmlrpc 2026-08-26 15:18:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:60354 https://access.redhat.com/errata/RHSA-2026:60354

Comment 55 errata-xmlrpc 2026-08-31 04:06:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:61253 https://access.redhat.com/errata/RHSA-2026:61253

Comment 56 Jon Orris 2026-09-16 17:18:53 UTC
This issue has been addressed in the following products:

  RHEM 1.2 for RHEL 10
  RHEM 1.2 for RHEL 9

Via RHSA-2026:68335 https://access.redhat.com/errata/RHSA-2026:68335

Comment 57 Jon Orris 2026-09-16 17:20:56 UTC
This issue has been addressed in the following products:

  RHEM 1.1 for RHEL 10
  RHEM 1.1 for RHEL 9

Via RHSA-2026:68334 https://access.redhat.com/errata/RHSA-2026:68334