PT-2026-37378 · Gnutls+4 · Gnutls+4

·

CVE-2026-42011

·

Published

2026-04-29

·

Updated

2026-07-22

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions gnutls versions prior to 3.8.13-1.1
Description A flaw exists where permitted name constraints are incorrectly ignored when previous Certificate Authorities (CAs) only have excluded name constraints. A remote attacker can exploit this to bypass critical name constraint checks during certificate validation, which may lead to the acceptance of invalid certificates and enable spoofing or man-in-the-middle attacks.
Recommendations Update to version 3.8.13-1.1.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:20611
ALSA-2026:20612
ALSA-2026:20613
BDU:2026-09661
CVE-2026-42011
ECHO-00BB-2656-B63A
OPENSUSE-SU-2026:10691-1
RHSA-2026:13274
RHSA-2026:20611
RHSA-2026:26409
SUSE-SU-2026:2822-1
SUSE-SU-2026:2923-1
SUSE-SU-2026:2924-1
USN-8284-1
USN-8539-1

Affected Products

Linuxmint
Red Os
Rocky Linux
Ubuntu
Gnutls