Ubuntu alert USN-8539-1 (gnutls28)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8539-1] GnuTLS vulnerabilities | |
| Date: | Tue, 14 Jul 2026 17:12:16 +0000 | |
| Message-ID: | <E1wjgg4-0000tB-5e@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8539-1 July 14, 2026 gnutls28 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in GnuTLS. Software Description: - gnutls28: GNU TLS library Details: Haruto Kimura discovered that GnuTLS did not properly apply permitted name constraints in certain certificate validation paths. A remote attacker could possibly use this issue to bypass certificate validation, leading to a machine-in-the-middle attack. (CVE-2026-42011) Oleh Konko discovered that GnuTLS incorrectly fell back to Common Name checks for certain URI and SRV subject alternative names. A remote attacker could possibly use this issue to bypass certificate validation, leading to a machine-in-the-middle attack. (CVE-2026-42012) Haruto Kimura and Joshua Rogers discovered that GnuTLS incorrectly fell back to Common Name checks when subject alternative names were oversized. A remote attacker could possibly use this issue to bypass certificate validation, leading to a machine-in-the-middle attack. (CVE-2026-42013) Luigino Camastra and Joshua Rogers discovered that GnuTLS had a use-after-free issue when changing PKCS#11 token security officer PINs in certain cases. An attacker could possibly use this issue to cause GnuTLS to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-42014) Zou Dikai discovered that GnuTLS did not properly validate PKCS#12 bag sizes in certain cases. An attacker could possibly use this issue to cause GnuTLS to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-42015) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS libgnutls30 3.6.13-2ubuntu1.12+esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS libgnutls30 3.5.18-1ubuntu1.6+esm4 Available with Ubuntu Pro Ubuntu 16.04 LTS libgnutls30 3.4.10-4ubuntu1.9+esm4 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8539-1 CVE-2026-42011, CVE-2026-42012, CVE-2026-42013, CVE-2026-42014, CVE-2026-42015
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmpWbX0ACgkQcpJm3tlz hgGgaRAAhRidSepElknG2ZVbEOrHkHk3bOndv5qfdjetqUHIygNMkye+z6cWagyO us5iZ8EhDEYt41PaEamqw/NvNNidYFfpQNONZ23At9Ir2tCUVtqAAwGAPoTCiiZj YDjR7vlTJjzKKwWZjbo6n/IVRMjMGMfYmRTAj0QxW9XEaNRkHOg8U3IhSvkRnUSa LLHG5AALjC/9oIZrP/fJv0Mep4qyZSKHWuJY/aAyViWe0dFNQn4NRPXpgTnhXkc8 Iet6+Ev3i0MRBk+q85vpD4edwNYxC1bFDcItx/AqULGk2bT1UjTITmwbRocYATOZ gFoXdYvrwIo4ICOHWih2O12ILni+61VxLPX16uXNuupwQTcbbGDyrz7gmglCUimd ngoC6AQp23kOS4yVl0jsMR1rn4vmD93qdRQz7yyLfnMmuNr1krUJVah41Z/kgxtb NAME3NlxSZ1IDRPc6zhq0qnuKh8GGK2Y5/yznaaaArizcIJy7h7gXA5yvKJAEbbY WLmwZ06TEfcP6s0K8u3FI/L7m1Zezg4ptnAI7/KvymkwRFenRbmc5djjw11XZjEG 6immwoI64h7BpyZLn+Xk93IOWv6e7k7q8AzdAoh4kQTPCo8cfOJxiarR31BrH7gT s9WmbSntAQKn6EEdhe7AUxGA+vLuG3/YbiYZjZXa2hUl/9BnUnA= =La5V -----END PGP SIGNATURE-----
