A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of nameConstraints labels, specifically for dNSName (DNS) or rfc822Name (email) constraints within excludedSubtrees or permittedSubtrees. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.
The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Gnutls | Gnu | - (including) | - (including) |
| Hardened_images | Redhat | - (including) | - (including) |
| Openshift_container_platform | Redhat | 4.0 (including) | 4.0 (including) |
| Enterprise_linux | Redhat | 6.0 (including) | 6.0 (including) |
| Enterprise_linux | Redhat | 7.0 (including) | 7.0 (including) |
| Enterprise_linux | Redhat | 8.0 (including) | 8.0 (including) |
| Enterprise_linux | Redhat | 9.0 (including) | 9.0 (including) |
| Enterprise_linux | Redhat | 10.0 (including) | 10.0 (including) |
| Red Hat Enterprise Linux 10 | RedHat | gnutls-0:3.8.10-4.el10_2 | * |
| Red Hat Enterprise Linux 10.0 Extended Update Support | RedHat | gnutls-0:3.8.9-9.el10_0.19 | * |
| Red Hat Enterprise Linux 8 | RedHat | gnutls-0:3.6.16-8.el8_10.6 | * |
| Red Hat Enterprise Linux 8 | RedHat | gnutls-0:3.6.16-8.el8_10.6 | * |
| Red Hat Enterprise Linux 9 | RedHat | gnutls-0:3.8.10-4.el9_8 | * |
| Red Hat Enterprise Linux 9 | RedHat | gnutls-0:3.8.10-4.el9_8 | * |
| Red Hat Hardened Images | RedHat | gnutls-main-3.8.13-1.hum1 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/cds-rhel9:1781525684 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/haproxy-rhel9:1781525671 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/installer-rhel9:1781525693 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/rhua-rhel9:1781525739 | * |
| Gnutls28 | Ubuntu | devel | * |
| Gnutls28 | Ubuntu | esm-infra/xenial | * |
| Gnutls28 | Ubuntu | fips-preview/jammy | * |
| Gnutls28 | Ubuntu | fips-updates/jammy | * |
| Gnutls28 | Ubuntu | fips-updates/noble | * |
| Gnutls28 | Ubuntu | jammy | * |
| Gnutls28 | Ubuntu | noble | * |
| Gnutls28 | Ubuntu | questing | * |
| Gnutls28 | Ubuntu | resolute | * |
| Gnutls28 | Ubuntu | upstream | * |
Improperly handled case sensitive data can lead to several possible consequences, including: