CVE-2026-42009
7.5 HIGHA flaw was found in gnutls
Published: 2026-05-18 · Last updated: 2026-06-08
Severity and scoring
- CVSS
- 7.5 HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- CWE
- CWE-475
Affected products
| Vendor | Product |
|---|---|
| gnu | enterprise_linux, enterprise_linux_for_els, enterprise_linux_for_eus |
| redhat | enterprise_linux, enterprise_linux_for_els, enterprise_linux_for_eus |
Description
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-42009
- [Other]https://access.redhat.com/errata/RHSA-2026:13274
- [Other]https://access.redhat.com/errata/RHSA-2026:20611
- [Other]https://access.redhat.com/errata/RHSA-2026:20612
- [Other]https://access.redhat.com/errata/RHSA-2026:20613
- [Other]https://access.redhat.com/security/cve/CVE-2026-42009
- [Other]https://bugzilla.redhat.com/show_bug.cgi?id=2467279
Related CVEs
Same vendor
- CVE-2026-1767 — A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component (5.6 MEDIUM)
- CVE-2026-1766 — A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 com... (5.6 MEDIUM)
- CVE-2026-11793 — A stack buffer overflow flaw was found in 389 Directory Server (4.9 MEDIUM)
- CVE-2026-11790 — A flaw was found in 389 Directory Server (4.9 MEDIUM)
- CVE-2026-11789 — A flaw was found in 389 Directory Server (4.9 MEDIUM)