Bug 2456333 (CVE-2026-32281) - CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation
Summary: CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via ine...
Keywords:
Status: NEW
Alias: CVE-2026-32281
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2456732
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-04-08 02:01 UTC by OSIDB Bzimport
Modified: 2026-06-18 12:18 UTC (History)
163 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:19135 0 None None None 2026-05-19 16:07:37 UTC
Red Hat Product Errata RHSA-2026:19353 0 None None None 2026-05-19 21:39:20 UTC
Red Hat Product Errata RHSA-2026:19719 0 None None None 2026-05-20 16:41:11 UTC
Red Hat Product Errata RHSA-2026:19720 0 None None None 2026-05-20 16:53:35 UTC
Red Hat Product Errata RHSA-2026:19721 0 None None None 2026-05-20 16:48:45 UTC
Red Hat Product Errata RHSA-2026:20569 0 None None None 2026-05-26 03:20:06 UTC
Red Hat Product Errata RHSA-2026:20570 0 None None None 2026-05-26 03:17:20 UTC
Red Hat Product Errata RHSA-2026:20571 0 None None None 2026-05-26 03:20:55 UTC
Red Hat Product Errata RHSA-2026:22141 0 None None None 2026-06-01 02:07:16 UTC
Red Hat Product Errata RHSA-2026:22309 0 None None None 2026-06-01 11:50:09 UTC
Red Hat Product Errata RHSA-2026:23102 0 None None None 2026-06-04 02:05:10 UTC
Red Hat Product Errata RHSA-2026:23103 0 None None None 2026-06-04 01:42:17 UTC
Red Hat Product Errata RHSA-2026:24337 0 None None None 2026-06-08 01:46:30 UTC
Red Hat Product Errata RHSA-2026:24470 0 None None None 2026-06-08 13:15:46 UTC
Red Hat Product Errata RHSA-2026:24716 0 None None None 2026-06-09 06:47:38 UTC
Red Hat Product Errata RHSA-2026:26054 0 None None None 2026-06-15 19:35:14 UTC
Red Hat Product Errata RHSA-2026:26447 0 None None None 2026-06-16 22:50:31 UTC
Red Hat Product Errata RHSA-2026:27076 0 None None None 2026-06-18 12:18:20 UTC

Description OSIDB Bzimport 2026-04-08 02:01:26 UTC
Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

Comment 7 errata-xmlrpc 2026-05-19 16:07:28 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:19135 https://access.redhat.com/errata/RHSA-2026:19135

Comment 8 errata-xmlrpc 2026-05-19 21:39:11 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:19353 https://access.redhat.com/errata/RHSA-2026:19353

Comment 12 errata-xmlrpc 2026-05-20 16:41:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:19719 https://access.redhat.com/errata/RHSA-2026:19719

Comment 13 errata-xmlrpc 2026-05-20 16:48:36 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2026:19721 https://access.redhat.com/errata/RHSA-2026:19721

Comment 14 errata-xmlrpc 2026-05-20 16:53:28 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:19720 https://access.redhat.com/errata/RHSA-2026:19720

Comment 15 errata-xmlrpc 2026-05-26 03:17:11 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:20570 https://access.redhat.com/errata/RHSA-2026:20570

Comment 16 errata-xmlrpc 2026-05-26 03:19:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:20569 https://access.redhat.com/errata/RHSA-2026:20569

Comment 17 errata-xmlrpc 2026-05-26 03:20:47 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:20571 https://access.redhat.com/errata/RHSA-2026:20571

Comment 19 errata-xmlrpc 2026-06-01 02:07:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:22141 https://access.redhat.com/errata/RHSA-2026:22141

Comment 20 errata-xmlrpc 2026-06-01 11:50:00 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:22309 https://access.redhat.com/errata/RHSA-2026:22309

Comment 29 errata-xmlrpc 2026-06-04 01:42:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:23103 https://access.redhat.com/errata/RHSA-2026:23103

Comment 30 errata-xmlrpc 2026-06-04 02:05:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:23102 https://access.redhat.com/errata/RHSA-2026:23102

Comment 31 errata-xmlrpc 2026-06-08 01:46:21 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:24337 https://access.redhat.com/errata/RHSA-2026:24337

Comment 32 errata-xmlrpc 2026-06-08 13:15:38 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:24470 https://access.redhat.com/errata/RHSA-2026:24470

Comment 33 errata-xmlrpc 2026-06-09 06:47:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:24716 https://access.redhat.com/errata/RHSA-2026:24716

Comment 34 errata-xmlrpc 2026-06-15 19:35:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:26054 https://access.redhat.com/errata/RHSA-2026:26054

Comment 35 errata-xmlrpc 2026-06-16 22:50:22 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:26447 https://access.redhat.com/errata/RHSA-2026:26447

Comment 36 errata-xmlrpc 2026-06-18 12:18:12 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.16 for RHEL 8
  Red Hat Satellite 6.16 for RHEL 9

Via RHSA-2026:27076 https://access.redhat.com/errata/RHSA-2026:27076


Note You need to log in before you can comment on or make changes to this bug.