[CLSA-2026:1791498436] gnutls: Fix of CVE-2026-42011
Type:
security
Severity:
Important
Release date:
2026-10-08 22:27:26 UTC
Description:
- CVE-2026-42011: a CA carrying only excluded name constraints, or permitted ones of another name type, no longer causes the permitted name constraints of a CA below it to be dropped during chain verification. This corrects the els1 entry: 3.3.29 is affected through the APPEND path of gnutls_x509_ext_import_name_constraints()
CVEs fixed:
Updated packages:
  • gnutls-3.3.29-9.0.3.el7_6.tuxcare.els2.i686.rpm
    sha:5273bcc5430518d7c3159c6a3b979b0fddbae485b09309fd82eed1b6d7fb8e9a
  • gnutls-3.3.29-9.0.3.el7_6.tuxcare.els2.x86_64.rpm
    sha:74e9891375783f8b0c86a0df068fc03af0d7e577305bd07799f8cc400207c46e
  • gnutls-c++-3.3.29-9.0.3.el7_6.tuxcare.els2.i686.rpm
    sha:cfad02205fcd94d7f311a9e2a1ccdb5941378718ea09affdddb4b9c39e0cf74e
  • gnutls-c++-3.3.29-9.0.3.el7_6.tuxcare.els2.x86_64.rpm
    sha:e6cef5a538a2eaecb6ea02ebd19f80b6ecf80e265364122404ca340cac3860bf
  • gnutls-dane-3.3.29-9.0.3.el7_6.tuxcare.els2.i686.rpm
    sha:ff6d58462efb1bf6f9badd5b5fef34273ec99b19d08360364c6f65c7cf765d85
  • gnutls-dane-3.3.29-9.0.3.el7_6.tuxcare.els2.x86_64.rpm
    sha:1c80bd8a4202dfc19cfcc133bc56de66e659dc20806f3485ac9085fe3f874ab0
  • gnutls-devel-3.3.29-9.0.3.el7_6.tuxcare.els2.i686.rpm
    sha:a97dfb828c62bc45742387be046a84ae444d3a5bf9fc0137451f0a7ed39e51f8
  • gnutls-devel-3.3.29-9.0.3.el7_6.tuxcare.els2.x86_64.rpm
    sha:26748f17b2386a9399aa56a397d958f10f29493acdf70113369b7c15b97437f5
  • gnutls-utils-3.3.29-9.0.3.el7_6.tuxcare.els2.i686.rpm
    sha:99bc3181c5fad92fb52e336acd70838cca914ab1dd2ed045a9a4d3ad0db38029
  • gnutls-utils-3.3.29-9.0.3.el7_6.tuxcare.els2.x86_64.rpm
    sha:a0eaa7d96f957e1102ceee3c1e8376f273a7f1993e5097b9b421baf67a419d1f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.