[CLSA-2026:1784559374] Fix CVE(s): CVE-2026-42011, CVE-2026-42012, CVE-2026-42013
Type:
security
Severity:
Important
Release date:
2026-07-20 14:56:45 UTC
Description:
* SECURITY UPDATE: Name constraints bypass when prior CAs have only excluded constraints - debian/patches/CVE-2026-42011.patch: remove the empty-permitted early return in name_constraints_node_list_intersect in lib/x509/name_constraints.c so permitted name constraints of a subsequent CA still propagate when previous CAs only carried excluded constraints; also backport the upstream regression suites to tests/name-constraints-merge.c - CVE-2026-42011 * SECURITY UPDATE: Certificate validation bypass via oversized subject alternative name - debian/patches/CVE-2026-42013.patch: refactor the CN and DN-email fallback logic and disable the fallback when gnutls_x509_crt_get_subject_alt_name reports an oversized SAN (GNUTLS_E_SHORT_MEMORY_BUFFER) in gnutls_x509_crt_check_hostname2 and gnutls_x509_crt_check_email (lib/x509/hostname-verify.c, lib/x509/email-verify.c); also backport the upstream regression tests to tests/hostname-check.c and tests/cert-tests/email (with tests/cert-tests/email-certs/oversized-san.pem) - CVE-2026-42013 * SECURITY UPDATE: CN fallback not precluded by URI or SRV subject alternative names - debian/patches/CVE-2026-42012.patch: add GNUTLS_SAN_URI and GNUTLS_SAN_OTHERNAME_SRV to the PRECLUDES_CN_FALLBACK macro in lib/x509/hostname-verify.c so certificates presenting URI or SRV SANs no longer allow hostname matching against the common name per RFC 6125 6.4.4; backport SRV virtual-SAN awareness (lib/includes/gnutls/gnutls.h.in, lib/x509/common.h, lib/x509/virt-san.c, lib/x509/output.c, lib/x509/x509.c) and the get_alt_name othername virtualization fix so SRV othernames are recognized on 3.6.13; also backport the upstream regression tests to tests/hostname-check.c - CVE-2026-42012
Updated packages:
  • gnutls-bin_3.6.13-2ubuntu1.12+tuxcare.els6_amd64.deb
    sha:69a444806be99952b7ee8e86d0dbaa2a0c6bb400
  • gnutls-doc_3.6.13-2ubuntu1.12+tuxcare.els6_all.deb
    sha:6508046acb22dd210cd6c054b9b34f09ccae59d6
  • guile-gnutls_3.6.13-2ubuntu1.12+tuxcare.els6_amd64.deb
    sha:c87ea31d71d96afa9bac0ac4ee20982902239a62
  • libgnutls-dane0_3.6.13-2ubuntu1.12+tuxcare.els6_amd64.deb
    sha:8e4035350668761ab31e0c7f3d3cef5ccfa7c1bf
  • libgnutls-openssl27_3.6.13-2ubuntu1.12+tuxcare.els6_amd64.deb
    sha:2648797f3dbcb4ca930142091abd30c536e3b17b
  • libgnutls28-dev_3.6.13-2ubuntu1.12+tuxcare.els6_amd64.deb
    sha:5c9fcb46470ce61ba467c6e9ccf6003e24d05da7
  • libgnutls30_3.6.13-2ubuntu1.12+tuxcare.els6_amd64.deb
    sha:0220a46b809e90185eafdf21049062466fb5bc7e
  • libgnutlsxx28_3.6.13-2ubuntu1.12+tuxcare.els6_amd64.deb
    sha:94ba357399f888ea3b9641d3bfc3dc1f2289c47c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.