CVE-2026-3833
EUVD-2026-2640330.04.2026, 18:16
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gnu | gnutls | - |
| redhat | hardened_images | - |
| redhat | openshift_container_platform | 4.0 |
| redhat | enterprise_linux | 6.0 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
| redhat | enterprise_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| gnutls |
| ||||||||||||
| gnutls-guile |
| ||||||||||||
| libgnutls-devel |
| ||||||||||||
| libgnutls30 |
| ||||||||||||
| libgnutls30-32bit |
| ||||||||||||
| libgnutls30-hmac |
| ||||||||||||
| libgnutls30-hmac-32bit |
| ||||||||||||
| libgnutlsxx-devel |
| ||||||||||||
| libgnutlsxx28 |
| ||||||||||||
| libgnutlsxx30 |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||
|---|---|---|---|---|---|
| gnutls |
| ||||
| gnutls-c |
| ||||
| gnutls-dane |
| ||||
| gnutls-devel |
| ||||
| gnutls-utils |
|
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| gnutls |
| ||
| gnutls-c++ |
| ||
| gnutls-c++-debuginfo |
| ||
| gnutls-dane |
| ||
| gnutls-dane-debuginfo |
| ||
| gnutls-debuginfo |
| ||
| gnutls-debugsource |
| ||
| gnutls-devel |
| ||
| gnutls-utils |
| ||
| gnutls-utils-debuginfo |
|
Common Weakness Enumeration
Vulnerability Media Exposure
References