CVE-2026-42011: Gnutls: gnutls: security bypass due to incorrect name constraint handling
A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems.
Other sources
libgnutls: Fix intersecting empty constraints Permitted name constraints were wrongfully ignored when prior CAs only had excluded name constraints, resulting in a name constraint bypass. Reported by .
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/gnutls28to a version that resolves this vulnerability.Fixed in 3.7.1-5+deb11u10Fixed in 3.7.9-2+deb12u7Fixed in 3.8.9-3+deb13u4Fixed in 3.8.13-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42011?
CVE-2026-42011 has been classified with a medium severity rating due to security bypass vulnerabilities.
How do I fix CVE-2026-42011?
To mitigate CVE-2026-42011, update GnuTLS to the latest version where the flaw has been patched.
What kind of applications are affected by CVE-2026-42011?
CVE-2026-42011 affects applications that utilize the GnuTLS library for handling secure communication.
Can CVE-2026-42011 be exploited remotely?
Yes, CVE-2026-42011 can be exploited by a remote attacker due to the flaw in name constraint handling.
What is the impact of CVE-2026-42011 on secure communications?
CVE-2026-42011 can lead to unauthorized bypass of security checks, compromising the integrity of secure communications.