CVE-2026-3833

Red Hat Security Advisory: Red Hat Update Infrastructure 5.3 Technology Preview security update

Beschreibung

Ein Fehler wurde in gnutls gefunden. Diese Schwachstelle tritt auf, weil gnutls fallbezogene Vergleiche von `nameConstraints`-Labels durchführt, insbesondere für `dNSName` (DNS) oder `rfc822Name` (E-Mail)-Beschränkungen innerhalb der `excludedSubtrees` oder `permittedSubtrees`. Ein Fernangreifer kann dies ausnutzen, indem er ein Blattzertifikat mit Groß-/Kleinschreibungsunterschieden im Subject Alternative Name (SAN) erstellt. Dadurch wird eine Richtlinie umgangen und ein Zertifikat, das abgelehnt werden sollte, wird stattdessen akzeptiert. Dies könnte zu unbefugtem Zugriff oder Offenlegung von Informationen führen.

Metriken

Severity
high
kein öffentlicher PoC bekannt
7.4
Quelle: nvd-v3
45.1 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.6 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-24 11:15 UTC
CWE-178

Weakness-Klassen (CWE)

  • CWE-178Base

    Improper Handling of Case Sensitivity

    The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-09-10 10:17 UTC· secalert@redhat.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/3xxx/CVE-2026-3833.json">CVE-2026-3833</a>
    • Reference: https://access.redhat.com/errata/RHSA-2026:62549
  2. CVE Modified2026-09-03 13:05 UTC· secalert@redhat.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/3xxx/CVE-2026-3833.json">CVE-2026-3833</a>
    • Reference: https://access.redhat.com/errata/RHSA-2026:59831
  3. CVE Modified2026-09-01 13:19 UTC· secalert@redhat.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/3xxx/CVE-2026-3833.json">CVE-2026-3833</a>
  4. CVE Modified2026-08-31 16:17 UTC· secalert@redhat.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/3xxx/CVE-2026-3833.json">CVE-2026-3833</a>
  5. CVE Modified2026-08-26 23:17 UTC· secalert@redhat.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/3xxx/CVE-2026-3833.json">CVE-2026-3833</a>
    • Reference: https://access.redhat.com/errata/RHSA-2026:13274
    • Reference: https://access.redhat.com/errata/RHSA-2026:20611
    • Reference: https://access.redhat.com/errata/RHSA-2026:20612

Betroffene Betriebssysteme

  • linux

    ubuntu / coreutilsjammy

  • linux

    ubuntu / coreutilsnoble

  • linux

    ubuntu / coreutilsresolute

  • linux

    debian / debian_linux11.0

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux10.2

  • linux

    redhat / enterprise_linux6.0

  • linux

    redhat / enterprise_linux7.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    redhat / enterprise_linux9.8

  • linux

    redhat / enterprise_linux_for_els10.2

  • linux

    redhat / enterprise_linux_for_els8.10

  • linux

    redhat / enterprise_linux_for_els9.8

  • linux

    redhat / enterprise_linux_for_eus10.2

  • linux

    redhat / enterprise_linux_for_eus9.8

  • linux

    redhat / enterprise_linux_for_ibm_z_systems10.2

  • linux

    redhat / enterprise_linux_for_ibm_z_systems8.0_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems9.0_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_els10.2

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_els8.10

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_els9.8

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus10.2

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus9.8

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • Apple

    iOS18.7.10

  • Apple

    iOS26.6.1

  • Apple

    iPadOS18.7.10

  • Apple

    iPadOS26.6.1

  • Apple

    macOSTahoe 26.6.2

  • bitnami

    jre1.9.0

  • bitnami

    nginx-gateway0.1.17

  • bitnami

    nginx-gateway-fabric1.3.0

  • bitnami

    postgresql15.0.0

  • bitnami

    postgresql16.0.0

  • bitnami

    postgresql17.0.0

  • bitnami

    postgresql18.0.0

  • bitnami

    python-min3.10.0

  • bitnami

    python-min3.11.0

  • bitnami

    python-min3.12.0

  • bitnami

    python-min3.13.0

  • bitnami

    python-min3.14.0

  • f5

    dos4.3.0 – 4.7.0

  • f5

    dos

  • f5

    nginx_gateway_fabric1.3.0 – 1.6.2

  • f5

    nginx_gateway_fabric2.0.0 – 2.5.1

  • f5

    nginx_ingress_controller3.5.0 – 3.7.2

  • f5

    nginx_ingress_controller4.0.0 – 4.0.1

  • f5

    nginx_ingress_controller5.0.0 – 5.4.1

Quellen & Referenzen

Verknüpfte CVEs

93 weitere CVEs anzeigen
IDCVE-2026-3833
Red Hat Security Advisory: Red Hat Update Infrastructure 5.3 Technology Preview security update — CVE-2026-3833 | NEOSEC Intel