CVE-2026-42012
Publication date 30 April 2026
Last updated 22 May 2026
Ubuntu priority
Description
Certificates containing URI or SRV Subject Alternative Names would fall back to checking DNS hostnames against Common Name, allowing potential misuse of such certificates beyond their original purpose.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| gnutls28 | 26.04 LTS resolute |
Fixed 3.8.12-2ubuntu1.1
|
| 25.10 questing |
Fixed 3.8.9-3ubuntu2.2
|
|
| 24.04 LTS noble |
Fixed 3.8.3-1.1ubuntu3.6
|
|
| 22.04 LTS jammy |
Fixed 3.7.3-4ubuntu1.9
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
References
Related Ubuntu Security Notices (USN)
- USN-8284-1
- GnuTLS vulnerabilities
- 20 May 2026