gnutls compares nameConstraints labels using a case-sensitive memcmp path without an ascii-casefold canonicalization step. when excludedSubtrees/permittedSubtrees dNSName (dns) or rfc822Name (email) constraints are present, attacker-controlled casing differences in the leaf certificate SAN can cause a false accept (policy bypass) where the certificate should be rejected.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:20611 https://access.redhat.com/errata/RHSA-2026:20611
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:20613 https://access.redhat.com/errata/RHSA-2026:20613
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:20612 https://access.redhat.com/errata/RHSA-2026:20612