[CLSA-2026:1784303329] Fix CVE(s): CVE-2026-42012, CVE-2026-42013, CVE-2026-42015
Type:
security
Severity:
Important
Release date:
2026-07-17 15:49:16 UTC
Description:
* SECURITY UPDATE: CN fallback not precluded by URI SAN - debian/patches/CVE-2026-42012.patch: treat a URI subject alternative name as precluding the fallback to Common Name hostname matching, per RFC 6125 6.4.4, in lib/x509/hostname-verify.c. - CVE-2026-42012 * SECURITY UPDATE: CN/DN fallback not precluded by oversized SAN - debian/patches/CVE-2026-42013.patch: keep the CN (hostname) and DN-email fallbacks disabled when a subject alternative name is oversized instead of silently ignoring it, per RFC 6125 6.4.4, in lib/x509/hostname-verify.c and lib/x509/email-verify.c. - CVE-2026-42013 * SECURITY UPDATE: PKCS#12 bag out-of-bounds write - debian/patches/CVE-2026-42015.patch: fix an off-by-one in the PKCS#12 bag element bounds check that allowed writing past the 32-element array, in lib/x509/pkcs12_bag.c. - CVE-2026-42015
Updated packages:
  • gnutls-bin_3.4.10-4ubuntu1.9+tuxcare.els4_amd64.deb
    sha:d11a7c0b3dd9fee0de484398b153cdbdd0da191c
  • gnutls-doc_3.4.10-4ubuntu1.9+tuxcare.els4_all.deb
    sha:e4d3a4a54ca6bd47bebe246458f73ad7fe4d4ddb
  • guile-gnutls_3.4.10-4ubuntu1.9+tuxcare.els4_amd64.deb
    sha:d49afe819ea7457f7988939748cacdceccb1743e
  • libgnutls-dev_3.4.10-4ubuntu1.9+tuxcare.els4_amd64.deb
    sha:0ad84850cc739c45a66ff7eeca380d697b1101f6
  • libgnutls-openssl27_3.4.10-4ubuntu1.9+tuxcare.els4_amd64.deb
    sha:ae31d106f96e12ac79a3d0f0f5540d9003251d65
  • libgnutls28-dev_3.4.10-4ubuntu1.9+tuxcare.els4_amd64.deb
    sha:14d443cba1f86f72f35a22c1a9a4ac0f0da65bc9
  • libgnutls30_3.4.10-4ubuntu1.9+tuxcare.els4_amd64.deb
    sha:26a75a0d510ee0d7e614b561be0c519e21e6c6f7
  • libgnutlsxx28_3.4.10-4ubuntu1.9+tuxcare.els4_amd64.deb
    sha:e810890d4c1e335ee9fdd7f77f4fc3958e283e05
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.