漏洞概述 漏洞编号: Bug 2467441 (CVE-2026-42012) 漏洞名称: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs 报告时间: 2026-05-06 19:17 UTC 修改时间: 2026-05-26 21:24 UTC 状态: NEW 优先级: medium 严重程度: medium 影响范围 产品: Security Response 组件: vulnerability 硬件: All 操作系统: Linux 目标里程碑: Product Security 修复方案 描述: - libgnutls: Suppress CN fallback in presence of URI and SRV SAN - Certificates containing URI or SRV Subject Alternative Names no longer fall back to checking DNS hostnames against Common Name to avoid potential misuse of such certificates beyond their original purpose. 其他信息 CC列表: 7 users 环境: 未指定 最后关闭: 未指定 Embargoed: 未指定 附件 附件名称: Terms of Use 描述: - libgnutls: Suppress CN fallback in presence of URI and SRV SAN - Certificates containing URI or SRV Subject Alternative Names no longer fall back to checking DNS hostnames against Common Name to avoid potential misuse of such certificates beyond their original purpose. 备注 需要登录才能评论或对此bug进行更改。