CVE-2026-42012: Gnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sans
A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.
Other sources
Gnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sans
— Microsoft
libgnutls: Suppress CN fallback in presence of URI and SRV SAN Certificates containing URI or SRV Subject Alternative Names no longer fall back to checking DNS hostnames against Common Name to avoid potential misuse of such certificates beyond their original purpose.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.8.13-1 - Upgrade
Upgrade
debian/gnutls28to a version that resolves this vulnerability.Fixed in 3.7.1-5+deb11u10Fixed in 3.7.9-2+deb12u7Fixed in 3.8.9-3+deb13u4Fixed in 3.8.13-1
Event History
Frequently Asked Questions
What is CVE-2026-42012?
CVE-2026-42012 is a vulnerability in gnutls that allows for certificate validation bypass due to improper handling of URI and SRV Subject Alternative Names.
What is the severity of CVE-2026-42012?
CVE-2026-42012 has a high severity rating of 7.1.
How can I fix CVE-2026-42012?
To fix CVE-2026-42012, upgrade to the latest version of gnutls that addresses this vulnerability.
What could an attacker do with CVE-2026-42012?
An attacker could exploit CVE-2026-42012 by presenting a specially crafted certificate that may bypass the certificate validation process.
Who is affected by CVE-2026-42012?
Users of debian/gnutls28 are potentially affected by CVE-2026-42012.