Bug 2537991 (CVE-2026-93602)

Summary: CVE-2026-93602 rustls-webpki: rustls-webpki: Certificate Revocation Check Bypass via Faulty CRL Logic
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: akhatavk, anpicker, anthomas, aos-team-art-private, aprice, asdas, bbrownin, blitton, bparees, brasmith, cochase, dbosanac, doconnor, dpaolell, dranck, dschmidt, eborisov, ehelms, gbenhaim, ggainey, gotiwari, hasun, hoberger, jcantril, jdelft, jfula, jhorak, jlanda, jowilson, jpasqual, jreimann, jsamir, jupierce, juwatts, kshier, lball, lgarciaa, lpele, mbarnett, mbiarnes, mdellweg, mdessi, mhulan, mrizzi, mvyas, ngough, niyer, nmoumoul, nyancey, oezr, ometelka, osousa, pcattana, pcreech, ppalepu, ppostler, prdhamdh, ptisnovs, rchan, rekumar, rhel-process-autobot, rjohnson, rojacob, sarad, sghai, sidsharm, simaishi, smallamp, sprizend, stcannon, suppawar, syedriko, tmalecek, twaugh, veshanka, vlaad, vvoronko, watson-tool-maintainers, xdharmai, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in rustls-webpki. The component contains faulty Certificate Revocation List (CRL) authority-matching logic, which incorrectly compares only the first distribution point against each CRL's issuing distribution point, ignoring others. This vulnerability allows an attacker with a compromised trusted issuing authority to present revoked certificates that bypass revocation checks, potentially leading to the acceptance of invalid certificates.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-22 16:27:25 UTC
rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against each CRL's IssuingDistributionPoint, ignoring additional distributionPoints. Attackers with a compromised trusted issuing authority can present revoked certificates that pass revocation checks under UnknownStatusPolicy::Allow, or cause incorrect errors under the default deny policy.