Release date:
2026-07-17 15:49:16 UTC
Description:
* SECURITY UPDATE: CN fallback not precluded by URI SAN
- debian/patches/CVE-2026-42012.patch: treat a URI subject
alternative name as precluding the fallback to Common Name
hostname matching, per RFC 6125 6.4.4, in
lib/x509/hostname-verify.c.
- CVE-2026-42012
* SECURITY UPDATE: CN/DN fallback not precluded by oversized SAN
- debian/patches/CVE-2026-42013.patch: keep the CN (hostname) and
DN-email fallbacks disabled when a subject alternative name is
oversized instead of silently ignoring it, per RFC 6125 6.4.4, in
lib/x509/hostname-verify.c and lib/x509/email-verify.c.
- CVE-2026-42013
* SECURITY UPDATE: PKCS#12 bag out-of-bounds write
- debian/patches/CVE-2026-42015.patch: fix an off-by-one in the
PKCS#12 bag element bounds check that allowed writing past the
32-element array, in lib/x509/pkcs12_bag.c.
- CVE-2026-42015
Updated packages:
-
gnutls-bin_3.4.10-4ubuntu1.9+tuxcare.els4_amd64.deb
sha:d11a7c0b3dd9fee0de484398b153cdbdd0da191c
-
gnutls-doc_3.4.10-4ubuntu1.9+tuxcare.els4_all.deb
sha:e4d3a4a54ca6bd47bebe246458f73ad7fe4d4ddb
-
guile-gnutls_3.4.10-4ubuntu1.9+tuxcare.els4_amd64.deb
sha:d49afe819ea7457f7988939748cacdceccb1743e
-
libgnutls-dev_3.4.10-4ubuntu1.9+tuxcare.els4_amd64.deb
sha:0ad84850cc739c45a66ff7eeca380d697b1101f6
-
libgnutls-openssl27_3.4.10-4ubuntu1.9+tuxcare.els4_amd64.deb
sha:ae31d106f96e12ac79a3d0f0f5540d9003251d65
-
libgnutls28-dev_3.4.10-4ubuntu1.9+tuxcare.els4_amd64.deb
sha:14d443cba1f86f72f35a22c1a9a4ac0f0da65bc9
-
libgnutls30_3.4.10-4ubuntu1.9+tuxcare.els4_amd64.deb
sha:26a75a0d510ee0d7e614b561be0c519e21e6c6f7
-
libgnutlsxx28_3.4.10-4ubuntu1.9+tuxcare.els4_amd64.deb
sha:e810890d4c1e335ee9fdd7f77f4fc3958e283e05
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.