RHSA-2026:43575MediumCVSS 8.2
Red Hat Security Advisory: gnutls security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2026-3833 — gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison CVE-2026-42011 — gnutls: gnutls: Security bypass due to incorrect name constraint handling CVE-2026-42012 — gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs CVE-2026-42013 — gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name CVE-2026-42014 — gnutls: gnutls: Use-after-free in gnutls_pkcs11_token_set_pin CVE-2026-42015 — gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:43575
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2445763
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2467437
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2467441
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2467448
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2467451
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2467678
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_43575.json