CVE-2026-42012: Red Hat Cert Manager Support For Red Hat Openshift Release 1.20
High severity, CVSS 7.1. EPSS: 0.5% chance of exploitation in the next 30 days.
A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.
Affected products
- Red Hat Cert Manager Support For Red Hat Openshift Release 1.20: before 1790598593 (fixed in 1790598593)
- Red Hat Red Hat Discovery 2: before 1782159791 (fixed in 1782159791); before 1782166952 (fixed in 1782166952)
- Red Hat Red Hat Enterprise Linux 10: before 0:3.8.10-4.el10_2 (fixed in 0:3.8.10-4.el10_2)
- Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support: before 0:3.8.9-9.el10_0.19 (fixed in 0:3.8.9-9.el10_0.19)
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support: before 0:3.3.29-9.el7_9.2 (fixed in 0:3.3.29-9.el7_9.2)
- Red Hat Red Hat Enterprise Linux 8: before 0:3.6.16-8.el8_10.6 (fixed in 0:3.6.16-8.el8_10.6)
- Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support: before 0:3.6.14-10.el8_4.1 (fixed in 0:3.6.14-10.el8_4.1); before 0:4.13-3.el8_4.1 (fixed in 0:4.13-3.el8_4.1)
- Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On: before 0:3.6.14-10.el8_4.1 (fixed in 0:3.6.14-10.el8_4.1); before 0:4.13-3.el8_4.1 (fixed in 0:4.13-3.el8_4.1)
- Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: before 0:3.6.16-5.el8_6.5 (fixed in 0:3.6.16-5.el8_6.5); before 0:4.13-3.el8_6.2 (fixed in 0:4.13-3.el8_6.2)
- Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On: before 0:3.6.16-5.el8_6.5 (fixed in 0:3.6.16-5.el8_6.5); before 0:4.13-3.el8_6.2 (fixed in 0:4.13-3.el8_6.2)
- Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service: before 0:3.6.16-7.el8_8.4 (fixed in 0:3.6.16-7.el8_8.4); before 0:4.13-4.el8_8.1 (fixed in 0:4.13-4.el8_8.1)
- Red Hat Red Hat Enterprise Linux 8.8 Update Services For SAP Solutions: before 0:3.6.16-7.el8_8.4 (fixed in 0:3.6.16-7.el8_8.4); before 0:4.13-4.el8_8.1 (fixed in 0:4.13-4.el8_8.1)
- Red Hat Red Hat Enterprise Linux 9: before 0:3.8.10-4.el9_8 (fixed in 0:3.8.10-4.el9_8)
- Red Hat Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions: before 0:3.7.6-21.el9_2.7 (fixed in 0:3.7.6-21.el9_2.7)
- Red Hat Red Hat Enterprise Linux 9.4 Update Services For SAP Solutions: before 0:3.8.3-4.el9_4.6 (fixed in 0:3.8.3-4.el9_4.6)
- Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support: before 0:3.8.3-6.el9_6.4 (fixed in 0:3.8.3-6.el9_6.4)
- Red Hat Red Hat Hardened Images: before 3.8.13-1.hum1 (fixed in 3.8.13-1.hum1)
- Red Hat Red Hat Openshift Ai 3.4: before 1790703542 (fixed in 1790703542)
- Red Hat Red Hat Openshift Container Platform 4
- Red Hat Red Hat Update Infrastructure 5: before 1781525684 (fixed in 1781525684); before 1781525671 (fixed in 1781525671); before 1781525693 (fixed in 1781525693); before 1781525739 (fixed in 1781525739); before 1787241211 (fixed in 1787241211); before 1787135742 (fixed in 1787135742); …
Published 2026-05-26. Last modified 2026-10-02.