From 1dead2faec6320aaba321eb56f20d442df192b83 Mon Sep 17 00:00:00 2001
From: Alexander Sosedkin <asosedkin@redhat.com>
Date: Tue, 14 Apr 2026 17:41:30 +0200
Subject: [PATCH 1/2] x509/name_constraints: fix intersecting empty constraints

Permitted name constraints were wrongfully ignored
when prior CAs only had excluded name constraints,
resulting in a name constraint bypass.

With this change, they are taken into account and propagate.

CVE: CVE-2026-42011
Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/1dead2faec6320aaba321eb56f20d442df192b83]

Reported-by: Haruto Kimura (Stella)
Fixes: #1824
Fixes: CVE-2026-42011
Fixes: GNUTLS-SA-2026-04-29-6
CVSS: 4.8 Medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Signed-off-by: Alexander Sosedkin <asosedkin@redhat.com>
Signed-off-by: Jakub Szczudlo <jakub.szczudlo@nokia.com>
---
 lib/x509/name_constraints.c | 3 ---
 1 file changed, 3 deletions(-)

diff --git a/lib/x509/name_constraints.c b/lib/x509/name_constraints.c
index 04722bdf4..232d466c4 100644
--- a/lib/x509/name_constraints.c
+++ b/lib/x509/name_constraints.c
@@ -723,9 +723,6 @@ static int name_constraints_node_list_intersect(
 	type_bitmask_t types_in_p1 = 0, types_in_p2 = 0;
 	static const unsigned char universal_ip[32] = { 0 };
 
-	if (permitted->size == 0 || permitted2->size == 0)
-		return GNUTLS_E_SUCCESS;
-
 	/* make sorted views of the arrays */
 	ret = ensure_sorted(permitted);
 	if (ret < 0) {
-- 
2.53.0

