AZL-105176

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105176.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-105176
Upstream
Published
2026-09-27T10:16:58Z
Modified
2026-10-01T14:15:49Z
Summary
CVE-2026-89133 affecting package mariadb 10.11.19-1
Details

wolfSSL versions 5.9.2 and earlier contain a flaw in the X.509 certificate validation logic where it fails to properly enforce NameConstraints extensions when there is an unconstrained CA tier between a name-constrained intermediate CA and the leaf certificate. wolfSSL incorrectly accepted certificates for hostnames they shouldn't be allowed to cover, due to a chain-walking state-machine bug that resets the validation state when encountering an intermediate without NameConstraints, thereby bypassing cryptographic delegation controls. This defect exists in the default build configuration that makes use of certificates where name constraint extensions are used. Thanks to Jack Lloyd, PathDiff, and Ben Smyth for reporting the issue.

References

Affected packages

Azure Linux:3 / mariadb

Package

Name
mariadb
Purl
pkg:rpm/azure-linux/mariadb

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
10.11.19-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105176.json"