CVE-2026-42013
Publication date 30 April 2026
Last updated 20 May 2026
Ubuntu priority
Description
Validation of certificates with oversized Subject Alternative Names would fall back to checking DNS hostnames against Common Name.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| gnutls28 | 26.04 LTS resolute |
Fixed 3.8.12-2ubuntu1.1
|
| 25.10 questing |
Fixed 3.8.9-3ubuntu2.2
|
|
| 24.04 LTS noble |
Fixed 3.8.3-1.1ubuntu3.6
|
|
| 22.04 LTS jammy |
Fixed 3.7.3-4ubuntu1.9
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
References
Related Ubuntu Security Notices (USN)
- USN-8284-1
- GnuTLS vulnerabilities
- 20 May 2026