Vulnerability CVE-2026-42011: Information

Description

A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems.

Severity: HIGH (7.4)
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Published: May 7, 2026
Modified: May 7, 2026
Error type identifier: CWE-295

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
gnutls30sisyphus3.8.13-alt13.8.13-alt1ALT-PU-2026-7123-1417120Fixed
gnutls30p113.8.13-alt13.8.13-alt1ALT-PU-2026-7127-2417121Fixed
gnutls30p103.6.16-alt113.6.16-alt10ALT-PU-2026-7344-1417556Testing
gnutls30c10f23.6.16-alt113.6.16-alt10ALT-PU-2026-7348-1417557Testing

References to Advisories, Solutions, and Tools