fix SAN dNSName constraints matching
details
- Finding IDs
- F-LIBRESSL-NC-WILDCARD-001
- Status
- fixed publicly (GHSA metadata unconfirmed)
- Reported via
- private security contact
- Note
- public OpenBSD/LibreSSL commit cf3eec32e7a6 on 2026-04-13 fixes SAN dNSName name-constraints matching by replacing substring/suffix matching with exact DNSName constraint semantics and adding regression coverage. LibreSSL 4.3.0/4.3.1 include the fix; 4.3.1 release notes explicitly mention the SAN dNSName constraints fix and 4.3.2 stable includes it. GHSA-h674-q4g3-3g47 was not publicly accessible at verification time, so this is tracked as a public upstream fixed mapping rather than confirmed GHSA/CVE metadata.
F-LIBRESSL-NC-WILDCARD-001: Verification failures. Substring/suffix matching weakens DNS name-constraint enforcement. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-LIBRESSL-NC-WILDCARD-001
Security area (1seal assessment): Identity. DNS name constraints require exact or label-boundary matches instead of unrestricted suffix matches. Reviewed 21 Sep 2026.