CVE-2026-42012

Red Hat Security Advisory: Red Hat Update Infrastructure 5.3 Technology Preview security update

Beschreibung

Ein Fehler wurde in gnutls gefunden. Ein Fernangreifer könnte diese Schwachstelle ausnutzen, indem er ein speziell erstelltes Zertifikat präsentiert, das Uniform Resource Identifier (URI) oder Service (SRV) Subject Alternative Names (SANs) enthält. Dies könnte dazu führen, dass der Zertifikatsüberprüfungsprozess fälschlicherweise auf die Überprüfung von DNS-Hostnamen gegen den Common Name (CN) zurückgreift und dem Angreifer ermöglicht, legitime Dienste zu tarnen oder sensible Informationen abzufangen.

Metriken

Severity
high
kein öffentlicher PoC bekannt
7.1
Quelle: nvd-v3
28.6 %
Erhöht — CVE ist relevanter als mindestens 10 % der heute bewerteten CVEs.
0.4 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-24 11:15 UTC
CWE-295

Weakness-Klassen (CWE)

  • CWE-295Base

    Improper Certificate Validation

    The product does not validate, or incorrectly validates, a certificate.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-09-01 13:19 UTC· secalert@redhat.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/42xxx/CVE-2026-42012.json">CVE-2026-42012</a>
  2. CVE Modified2026-08-31 16:18 UTC· secalert@redhat.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/42xxx/CVE-2026-42012.json">CVE-2026-42012</a>
    • Reference: https://access.redhat.com/errata/RHSA-2026:13274
    • Reference: https://access.redhat.com/errata/RHSA-2026:20611
    • Reference: https://access.redhat.com/errata/RHSA-2026:20612
  3. CVE Modified2026-08-21 14:16 UTC· secalert@redhat.com
    • Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 7 Extended Lifecycle Support (+29)…, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support (+30)
  4. CVE Modified2026-08-21 13:17 UTC· secalert@redhat.com
    • Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 7 Extended Lifecycle Support (+29)Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 7 Extended Lifecycle Support (+29)
  5. CVE Translated2026-07-23 11:10 UTC· nvd@nist.gov
    • Translation: Title: Gnutls en RedHat, Description: Se encontró una falla en gnutls. Un atacante remoto podría explotar esta vulnerabilidad al presentar un certificado especialmente diseñado que contiene Nombres Alternativos del Sujeto (SANs) de Identificador Uniforme de Recursos (URI) o de Servicio (SRV). Esto podría causar que el proceso de validación del certificado recurra incorrectamente a la verificación de nombres de host DNS contra el Nombre Común (CN), lo que podría permitir al atacante suplantar servicios legítimos o interceptar información sensible.

Betroffene Betriebssysteme

  • linux

    ubuntu / coreutilsjammy

  • linux

    ubuntu / coreutilsnoble

  • linux

    ubuntu / coreutilsresolute

  • linux

    debian / debian_linux11.0

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux10.2

  • linux

    redhat / enterprise_linux6.0

  • linux

    redhat / enterprise_linux7.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    redhat / enterprise_linux9.8

  • linux

    redhat / enterprise_linux_for_els10.2

  • linux

    redhat / enterprise_linux_for_els8.10

  • linux

    redhat / enterprise_linux_for_els9.8

  • linux

    redhat / enterprise_linux_for_eus10.2

  • linux

    redhat / enterprise_linux_for_eus9.8

  • linux

    redhat / enterprise_linux_for_ibm_z_systems10.2

  • linux

    redhat / enterprise_linux_for_ibm_z_systems8.0_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems9.0_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_els10.2

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_els8.10

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_els9.8

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus10.2

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus9.8

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • Apple

    iOS18.7.10

  • Apple

    iOS26.6.1

  • Apple

    iPadOS18.7.10

  • Apple

    iPadOS26.6.1

  • Apple

    macOSTahoe 26.6.2

  • bitnami

    jre1.9.0

  • bitnami

    nginx-gateway0.1.17

  • bitnami

    nginx-gateway-fabric1.3.0

  • bitnami

    postgresql15.0.0

  • bitnami

    postgresql16.0.0

  • bitnami

    postgresql17.0.0

  • bitnami

    postgresql18.0.0

  • bitnami

    python-min3.10.0

  • bitnami

    python-min3.11.0

  • bitnami

    python-min3.12.0

  • bitnami

    python-min3.13.0

  • bitnami

    python-min3.14.0

  • f5

    dos4.3.0 – 4.7.0

  • f5

    dos

  • f5

    nginx_gateway_fabric1.3.0 – 1.6.2

  • f5

    nginx_gateway_fabric2.0.0 – 2.5.1

  • f5

    nginx_ingress_controller3.5.0 – 3.7.2

  • f5

    nginx_ingress_controller4.0.0 – 4.0.1

  • f5

    nginx_ingress_controller5.0.0 – 5.4.1

Quellen & Referenzen

Verknüpfte CVEs

93 weitere CVEs anzeigen
IDCVE-2026-42012