Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-42011

Опубликовано: 07 мая 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.4

Описание

A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems.

РелизСтатусПримечание
devel

not-affected

3.8.12-2ubuntu1.1
esm-infra-legacy/xenial

not-affected

code not present
esm-infra/bionic

released

3.5.18-1ubuntu1.6+esm4
esm-infra/focal

released

3.6.13-2ubuntu1.12+esm3
esm-infra/xenial

ignored

end of ESM support, was needs-triage
fips-preview/jammy

needed

fips-updates/jammy

released

3.7.3-4ubuntu1.9+Fips1
fips-updates/noble

released

3.8.3-1.1ubuntu3.6+Fips1.2
jammy

released

3.7.3-4ubuntu1.9
noble

released

3.8.3-1.1ubuntu3.6

Показывать по

EPSS

Процентиль: 39%
0.00475
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
redhat
3 месяца назад

A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems.

CVSS3: 7.4
nvd
3 месяца назад

A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems.

msrc
2 месяца назад

Gnutls: gnutls: security bypass due to incorrect name constraint handling

CVSS3: 7.4
debian
3 месяца назад

A flaw was found in gnutls. This vulnerability occurs because permitte ...

CVSS3: 7.4
redos
около 1 месяца назад

Уязвимость gnutls

EPSS

Процентиль: 39%
0.00475
Низкий

7.4 High

CVSS3