7.5highHigh

CVE-2026-42009

Gnu Gnutls

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.

What the metrics mean

  • It is reachable over a network, without needing local access.
  • For an attacker who can reach it, no special conditions are needed to exploit it.
  • To exploit it, no account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
7.5 (v3.1)
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness
CWE-475
Assigned by
secalert@redhat.com

Dates

Published
2026-05-18
Last modified
2026-09-04
Sources
NVD

Affected products

  • Gnu Gnutlsall versions
  • Redhat Hardened Imagesall versions
  • Redhat Openshift Container Platform4.0
  • Redhat Enterprise Linux6.0, 7.0, 8.0, 9.0, 9.8, 10.0, 10.2
  • Redhat Enterprise Linux For Els8.10, 9.8, 10.2
  • Redhat Enterprise Linux For Ibm Z Systems8.0 s390x, 9.0 s390x, 10.2
  • Redhat Enterprise Linux For Ibm Z Systems Els8.10, 9.8, 10.2
  • Redhat Enterprise Linux For Power Little Endian8.0 ppc64le, 9.0 ppc64le, 10.0, 10.2
  • Redhat Enterprise Linux For Power Little Endian Els8.10, 9.8, 10.2
  • Redhat Enterprise Linux For Eus9.8, 10.2
  • Redhat Enterprise Linux For Ibm Z Systems Eus9.8, 10.2
  • Redhat Enterprise Linux For Power Little Endian Eus9.8, 10.2

As listed in the NVD configuration data. Not a statement about your estate.

References