Incomplete X.509 implementation in GnuTLS v3.8.13 allows attackers controlling a subordinate Certificate Authority to bypass cross-domain PKI restrictions and issue unauthorized certificates.
https://www.rfc-editor.org/rfc/rfc5280#section-6.1.4
https://www.rfc-editor.org/rfc/rfc5280#section-4.2.1.10
https://gist.github.com/lkloliver/1f2a97cb8d0b31aa27b6bd0354358d7d