Fedora Account System
Red Hat Associate
Red Hat Customer
When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:8842 https://access.redhat.com/errata/RHSA-2026:8842
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:10169 https://access.redhat.com/errata/RHSA-2026:10169
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:10929 https://access.redhat.com/errata/RHSA-2026:10929
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:19022 https://access.redhat.com/errata/RHSA-2026:19022
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:19049 https://access.redhat.com/errata/RHSA-2026:19049
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:19132 https://access.redhat.com/errata/RHSA-2026:19132
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:19181 https://access.redhat.com/errata/RHSA-2026:19181
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:22450 https://access.redhat.com/errata/RHSA-2026:22450
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:22714 https://access.redhat.com/errata/RHSA-2026:22714
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:22937 https://access.redhat.com/errata/RHSA-2026:22937
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:23228 https://access.redhat.com/errata/RHSA-2026:23228
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:28038 https://access.redhat.com/errata/RHSA-2026:28038
This issue has been addressed in the following products: RHEM 1.0 for RHEL 9 Via RHSA-2026:36796 https://access.redhat.com/errata/RHSA-2026:36796
This issue has been addressed in the following products: Red Hat OpenStack Services on OpenShift 18.0 Via RHSA-2026:39810 https://access.redhat.com/errata/RHSA-2026:39810
Added rhem-1.1/flightctl affect and tracker. This stream was missing affects for this CVE since it went GA after the triage, but it's still vulnerable.
This issue has been addressed in the following products: RHEM 1.1 for RHEL 10 RHEM 1.1 for RHEL 9 Via RHSA-2026:41019 https://access.redhat.com/errata/RHSA-2026:41019