REDHAT-BUG-2467448: Medium severity GnuTLS libgnutls vulnerability
libgnutls: Suppress CN fallback for oversized SAN Validation of certificates with oversized Subject Alternative Names no longer falls back to checking DNS hostnames against Common Name.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Until systems are updated to the libgnutls release that suppresses Common Name (CN) fallback for oversized Subject Alternative Names (SAN), ensure certificate validation does not rely on CN fallback — require valid SAN entries for hostname matching or restrict acceptance of certificates lacking usable SANs.
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2467448?
The severity of REDHAT-BUG-2467448 is classified as medium with a score of 4.
What does REDHAT-BUG-2467448 address?
REDHAT-BUG-2467448 addresses the suppression of CN fallback for oversized Subject Alternative Names in GnuTLS.
How can I mitigate the issues described in REDHAT-BUG-2467448?
To mitigate REDHAT-BUG-2467448, ensure that you are using the latest version of GnuTLS that includes the fix.
Is REDHAT-BUG-2467448 a security vulnerability?
Yes, REDHAT-BUG-2467448 is considered a security vulnerability related to certificate validation in GnuTLS.
When was REDHAT-BUG-2467448 published?
REDHAT-BUG-2467448 was published on May 6, 2026.