CVE-2026-42013
EUVD-2026-3201126.05.2026, 22:16
A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| gnutls28 |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| gnutls |
| ||||||||||||||
| gnutls-guile |
| ||||||||||||||
| libgnutls-devel |
| ||||||||||||||
| libgnutls-openssl27 |
| ||||||||||||||
| libgnutls28 |
| ||||||||||||||
| libgnutls28-32bit |
| ||||||||||||||
| libgnutls30 |
| ||||||||||||||
| libgnutls30-32bit |
| ||||||||||||||
| libgnutls30-hmac |
| ||||||||||||||
| libgnutls30-hmac-32bit |
| ||||||||||||||
| libgnutlsxx-devel |
| ||||||||||||||
| libgnutlsxx28 |
| ||||||||||||||
| libgnutlsxx30 |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| gnutls |
| ||||||||||||
| gnutls-c |
| ||||||||||||
| gnutls-dane |
| ||||||||||||
| gnutls-devel |
| ||||||||||||
| gnutls-utils |
| ||||||||||||
| libtasn1 |
| ||||||||||||
| libtasn1-devel |
| ||||||||||||
| libtasn1-tools |
|
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| gnutls |
| ||
| gnutls-c++ |
| ||
| gnutls-c++-debuginfo |
| ||
| gnutls-dane |
| ||
| gnutls-dane-debuginfo |
| ||
| gnutls-debuginfo |
| ||
| gnutls-debugsource |
| ||
| gnutls-devel |
| ||
| gnutls-utils |
| ||
| gnutls-utils-debuginfo |
|
Common Weakness Enumeration
References