Release date:
2026-07-20 14:56:45 UTC
Description:
* SECURITY UPDATE: Name constraints bypass when prior CAs have only
excluded constraints
- debian/patches/CVE-2026-42011.patch: remove the empty-permitted early
return in name_constraints_node_list_intersect in
lib/x509/name_constraints.c so permitted name constraints of a
subsequent CA still propagate when previous CAs only carried excluded
constraints; also backport the upstream regression suites to
tests/name-constraints-merge.c
- CVE-2026-42011
* SECURITY UPDATE: Certificate validation bypass via oversized subject
alternative name
- debian/patches/CVE-2026-42013.patch: refactor the CN and DN-email
fallback logic and disable the fallback when
gnutls_x509_crt_get_subject_alt_name reports an oversized SAN
(GNUTLS_E_SHORT_MEMORY_BUFFER) in gnutls_x509_crt_check_hostname2 and
gnutls_x509_crt_check_email (lib/x509/hostname-verify.c,
lib/x509/email-verify.c); also backport the upstream regression tests to
tests/hostname-check.c and tests/cert-tests/email (with
tests/cert-tests/email-certs/oversized-san.pem)
- CVE-2026-42013
* SECURITY UPDATE: CN fallback not precluded by URI or SRV subject
alternative names
- debian/patches/CVE-2026-42012.patch: add GNUTLS_SAN_URI and
GNUTLS_SAN_OTHERNAME_SRV to the PRECLUDES_CN_FALLBACK macro in
lib/x509/hostname-verify.c so certificates presenting URI or SRV SANs no
longer allow hostname matching against the common name per RFC 6125
6.4.4; backport SRV virtual-SAN awareness (lib/includes/gnutls/gnutls.h.in,
lib/x509/common.h, lib/x509/virt-san.c, lib/x509/output.c, lib/x509/x509.c)
and the get_alt_name othername virtualization fix so SRV othernames are
recognized on 3.6.13; also backport the upstream regression tests to
tests/hostname-check.c
- CVE-2026-42012
Updated packages:
-
gnutls-bin_3.6.13-2ubuntu1.12+tuxcare.els6_amd64.deb
sha:69a444806be99952b7ee8e86d0dbaa2a0c6bb400
-
gnutls-doc_3.6.13-2ubuntu1.12+tuxcare.els6_all.deb
sha:6508046acb22dd210cd6c054b9b34f09ccae59d6
-
guile-gnutls_3.6.13-2ubuntu1.12+tuxcare.els6_amd64.deb
sha:c87ea31d71d96afa9bac0ac4ee20982902239a62
-
libgnutls-dane0_3.6.13-2ubuntu1.12+tuxcare.els6_amd64.deb
sha:8e4035350668761ab31e0c7f3d3cef5ccfa7c1bf
-
libgnutls-openssl27_3.6.13-2ubuntu1.12+tuxcare.els6_amd64.deb
sha:2648797f3dbcb4ca930142091abd30c536e3b17b
-
libgnutls28-dev_3.6.13-2ubuntu1.12+tuxcare.els6_amd64.deb
sha:5c9fcb46470ce61ba467c6e9ccf6003e24d05da7
-
libgnutls30_3.6.13-2ubuntu1.12+tuxcare.els6_amd64.deb
sha:0220a46b809e90185eafdf21049062466fb5bc7e
-
libgnutlsxx28_3.6.13-2ubuntu1.12+tuxcare.els6_amd64.deb
sha:94ba357399f888ea3b9641d3bfc3dc1f2289c47c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.