7.4

CVE-2026-3833

Exploit

Gnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison

A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gnu ≫ Gnutls Version -
Redhat ≫ Hardened Images Version -
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 9.0
Redhat ≫ Enterprise Linux Version 10.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.57% 0.435
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.4 2.2 5.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
RedHat 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CWE-178 Improper Handling of Case Sensitivity

The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.

https://bugzilla.redhat.com/show_bug.cgi?id=2445763
Third Party Advisory
Issue Tracking
https://gitlab.com/gnutls/gnutls/-/issues/1803
Vendor Advisory
Exploit
Issue Tracking
https://access.redhat.com/errata/RHSA-2026:13274
Third Party Advisory
Issue Tracking
https://access.redhat.com/errata/RHSA-2026:20611
https://access.redhat.com/errata/RHSA-2026:20612
https://access.redhat.com/errata/RHSA-2026:20613
https://access.redhat.com/errata/RHSA-2026:26319
https://access.redhat.com/errata/RHSA-2026:26409
https://access.redhat.com/errata/RHSA-2026:29197
https://access.redhat.com/errata/RHSA-2026:30004
https://access.redhat.com/errata/RHSA-2026:30849
https://access.redhat.com/errata/RHSA-2026:30850
https://access.redhat.com/errata/RHSA-2026:32962
https://access.redhat.com/errata/RHSA-2026:33125
https://access.redhat.com/security/cve/CVE-2026-3833
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:41921
https://access.redhat.com/errata/RHSA-2026:43575
https://access.redhat.com/errata/RHSA-2026:58981
https://access.redhat.com/errata/RHSA-2026:57402
https://access.redhat.com/errata/RHSA-2026:59831
https://access.redhat.com/errata/RHSA-2026:60019
https://access.redhat.com/errata/RHSA-2026:62549
https://access.redhat.com/errata/RHSA-2026:62409
https://access.redhat.com/errata/RHSA-2026:65851
https://access.redhat.com/errata/RHSA-2026:65839
https://access.redhat.com/errata/RHSA-2026:67857
https://access.redhat.com/errata/RHSA-2026:72502
https://access.redhat.com/errata/RHSA-2026:74674