Release date:
2026-07-17 06:09:11 UTC
Description:
* SECURITY UPDATE: name-constraints bypass with excluded-only parent CA
- debian/patches/CVE-2026-42011.patch: take permitted name
constraints into account when a prior CA in the chain carried only
excluded constraints, so a constrained sub-CA can no longer issue
certificates outside its permitted scope, in
lib/x509/name_constraints.c.
- CVE-2026-42011
* SECURITY UPDATE: CN fallback not precluded by URI SAN
- debian/patches/CVE-2026-42012.patch: treat a URI subject
alternative name as precluding the fallback to Common Name
hostname matching, per RFC 6125 6.4.4, in
lib/x509/hostname-verify.c.
- CVE-2026-42012
* SECURITY UPDATE: CN/DN fallback not precluded by oversized SAN
- debian/patches/CVE-2026-42013.patch: keep the CN (hostname) and
DN-email fallbacks disabled when a subject alternative name is
oversized instead of silently ignoring it, per RFC 6125 6.4.4, in
lib/x509/hostname-verify.c and lib/x509/email-verify.c.
- CVE-2026-42013
* SECURITY UPDATE: PKCS#12 bag out-of-bounds write
- debian/patches/CVE-2026-42015.patch: fix an off-by-one in the
PKCS#12 bag element bounds check that allowed writing past the
32-element array, in lib/x509/pkcs12_bag.c.
- CVE-2026-42015
Updated packages:
-
gnutls-bin_3.5.18-1ubuntu1.6+tuxcare.els5_amd64.deb
sha:abbb2923fceaef82371852fa625f30ecb6934c1d
-
gnutls-doc_3.5.18-1ubuntu1.6+tuxcare.els5_all.deb
sha:1a1b144df0fd5c181d2e63b1ef5daaefcdd8befd
-
libgnutls-dane0_3.5.18-1ubuntu1.6+tuxcare.els5_amd64.deb
sha:b78203e146274c5e0994af10a4f1cbba8e673669
-
libgnutls-openssl27_3.5.18-1ubuntu1.6+tuxcare.els5_amd64.deb
sha:5dd251532942898d64e6662fd852c2886ba4169c
-
libgnutls28-dev_3.5.18-1ubuntu1.6+tuxcare.els5_amd64.deb
sha:6433ae9f4408d64abfcd993eb6f9a005f19759c5
-
libgnutls30_3.5.18-1ubuntu1.6+tuxcare.els5_amd64.deb
sha:81e7b87bde1e58e79e1d4d0964e80e1af8f3f1f2
-
libgnutlsxx28_3.5.18-1ubuntu1.6+tuxcare.els5_amd64.deb
sha:494bb9b72cbab83fd4ec463501a09f24db414794
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.