Bug 2542493 (CVE-2026-91769) - CVE-2026-91769 php: php: Server impersonation via Common Name fallback in TLS verification
Summary: CVE-2026-91769 php: php: Server impersonation via Common Name fallback in TLS...
Keywords:
Status: NEW
Alias: CVE-2026-91769
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2543804
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-28 13:53 UTC by OSIDB Bzimport
Modified: 2026-09-30 05:50 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-28 13:53:06 UTC
PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires the CN to be ignored once the certificate presents any service identity, so a certificate carrying a non-matching DNS SAN was still accepted when its CN matched the requested peer_name. A certificate trusted by the client for one name can therefore be used to impersonate another.


Note You need to log in before you can comment on or make changes to this bug.