SB2026072529 - openEuler 22.03 LTS SP4 update for gnutls



SB2026072529 - openEuler 22.03 LTS SP4 update for gnutls

Published: July 25, 2026

Security Bulletin ID SB2026072529
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Improper Certificate Validation (CVE-ID: CVE-2026-3832)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass certificate revocation checks.

The vulnerability exists due to improper certificate status validation in OCSP response processing when validating a certificate against a multi-entry OCSP response. A remote attacker can supply a certificate status response with multiple entries to bypass certificate revocation checks.


2) Improper Certificate Validation (CVE-ID: CVE-2026-42012)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to misuse certificates beyond their intended purpose.

The vulnerability exists due to improper certificate validation in certificate hostname verification when processing certificates containing URI or SRV Subject Alternative Names. A remote attacker can present a specially crafted certificate to misuse certificates beyond their intended purpose.

Certificates with URI or SRV Subject Alternative Names may incorrectly fall back to checking DNS hostnames against the Common Name.


Remediation

Install update from vendor's website.