7.5highHigh
CVE-2026-42009
Gnu Gnutls
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.
What the metrics mean
- It is reachable over a network, without needing local access.
- For an attacker who can reach it, no special conditions are needed to exploit it.
- To exploit it, no account is needed.
- Beyond that, no action by a user is required.
Scoring
- CVSS
- 7.5 (v3.1)
- Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H- Weakness
- CWE-475
- Assigned by
- secalert@redhat.com
Dates
- Published
- 2026-05-18
- Last modified
- 2026-09-04
- Sources
- NVD
Affected products
- Gnu Gnutlsall versions
- Redhat Hardened Imagesall versions
- Redhat Openshift Container Platform4.0
- Redhat Enterprise Linux6.0, 7.0, 8.0, 9.0, 9.8, 10.0, 10.2
- Redhat Enterprise Linux For Els8.10, 9.8, 10.2
- Redhat Enterprise Linux For Ibm Z Systems8.0 s390x, 9.0 s390x, 10.2
- Redhat Enterprise Linux For Ibm Z Systems Els8.10, 9.8, 10.2
- Redhat Enterprise Linux For Power Little Endian8.0 ppc64le, 9.0 ppc64le, 10.0, 10.2
- Redhat Enterprise Linux For Power Little Endian Els8.10, 9.8, 10.2
- Redhat Enterprise Linux For Eus9.8, 10.2
- Redhat Enterprise Linux For Ibm Z Systems Eus9.8, 10.2
- Redhat Enterprise Linux For Power Little Endian Eus9.8, 10.2
As listed in the NVD configuration data. Not a statement about your estate.
References
- https://access.redhat.com/errata/RHSA-2026:13274
- https://access.redhat.com/errata/RHSA-2026:20611
- https://access.redhat.com/errata/RHSA-2026:20612
- https://access.redhat.com/errata/RHSA-2026:20613
- https://access.redhat.com/errata/RHSA-2026:26319
- https://access.redhat.com/errata/RHSA-2026:26409
- https://access.redhat.com/errata/RHSA-2026:29197
- https://access.redhat.com/errata/RHSA-2026:29794
- https://access.redhat.com/errata/RHSA-2026:30004
- https://access.redhat.com/errata/RHSA-2026:30849
- https://access.redhat.com/errata/RHSA-2026:30850
- https://access.redhat.com/errata/RHSA-2026:32962
- https://access.redhat.com/errata/RHSA-2026:33125
- https://access.redhat.com/errata/RHSA-2026:34372
- https://access.redhat.com/errata/RHSA-2026:34764