CVE-2026-42009 Details
Description
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.
A denial-of-service vulnerability has been identified in GnuTLS, specifically within the Datagram Transport Layer Security (DTLS) packet reordering logic. The issue arises because the comparator function, which orders DTLS packets by their sequence numbers, improperly manages packets with duplicate sequence numbers. This mismanagement can cause unstable packet ordering or undefined behavior, ultimately leading to a denial-of-service condition.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-475 | Undefined Behavior for Input to API | redhat-SADP |
| CWE-475 | Undefined Behavior for Input to API | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gnu gnutls | All versions |
CPE
Remediation
| |
| redhat hardened images | All versions |
CPE
Remediation
| |
| redhat openshift container platform | 4.0 |
CPE
Remediation
| |
| redhat enterprise linux | 6.0 7.0 8.0 9.0 9.8 10.0 10.2 |
CPE
Remediation
| |
| redhat enterprise linux for els | 8.10 9.8 10.2 |
CPE
Remediation
| |
| redhat enterprise linux for ibm z systems | 8.0_s390x 9.0_s390x 10.2 |
CPE
Remediation
| |
| redhat enterprise linux for ibm z systems els | 8.10 9.8 10.2 |
CPE
Remediation
| |
| redhat enterprise linux for power little endian | 8.0_ppc64le 9.0_ppc64le 10.0 10.2 |
CPE
Remediation
| |
| redhat enterprise linux for power little endian els | 8.10 9.8 10.2 |
CPE
Remediation
| |
| redhat enterprise linux for eus | 9.8 10.2 |
CPE
Remediation
| |
| redhat enterprise linux for ibm z systems eus | 9.8 10.2 |
CPE
Remediation
| |
| redhat enterprise linux for power little endian eus | 9.8 10.2 |
CPE
Remediation
| |
| redhat enterprise linux for update services for sap solutions | 9.8 |
CPE
Remediation
| |
| redhat enterprise linux server for power little endian update services for sap solutions | 9.8 |
CPE
Remediation
| |
Change History
55 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 18, 2026 | CVE Modified | redhat-SADP |
| Sep 17, 2026 | CVE Modified | [email protected] |
| Sep 4, 2026 | CVE Modified | redhat-SADP |
| Sep 3, 2026 | CVE Modified | [email protected] |
| Sep 3, 2026 | CVE Modified | [email protected] |
| Sep 1, 2026 | CVE Modified | redhat-SADP |
| Sep 1, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | redhat-SADP |
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 27, 2026 | CVE Modified | redhat-SADP |
| Aug 26, 2026 | CVE Modified | [email protected] |
| Aug 26, 2026 | CVE Modified | [email protected] |
| Aug 26, 2026 | CVE Modified | [email protected] |
| Aug 26, 2026 | CVE Modified | redhat-SADP |
| Aug 25, 2026 | CVE Modified | [email protected] |
| Aug 25, 2026 | CVE Modified | redhat-SADP |
| Aug 25, 2026 | CVE Modified | [email protected] |
| Aug 24, 2026 | CVE Modified | [email protected] |
| Aug 24, 2026 | CVE Modified | redhat-SADP |
| Aug 21, 2026 | CVE Modified | [email protected] |
| Aug 21, 2026 | CVE Modified | [email protected] |
| Jul 23, 2026 | CVE Modified | redhat-SADP |
| Jul 22, 2026 | CVE Modified | [email protected] |
| Jul 20, 2026 | CVE Modified | redhat-SADP |
| Jul 20, 2026 | CVE Modified | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 14, 2026 | CVE Modified | redhat-SADP |
| Jul 13, 2026 | CVE Modified | [email protected] |
| Jul 8, 2026 | CVE Modified | redhat-SADP |
| Jul 7, 2026 | CVE Modified | [email protected] |
| Jul 7, 2026 | CVE Modified | [email protected] |
| Jul 7, 2026 | CVE Modified | redhat-SADP |
| Jul 6, 2026 | CVE Modified | [email protected] |
| Jul 6, 2026 | CVE Modified | [email protected] |
| Jul 2, 2026 | CVE Modified | redhat-SADP |
| Jul 1, 2026 | CVE Modified | [email protected] |
| Jul 1, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | [email protected] |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 29, 2026 | CVE Modified | [email protected] |
| Jun 29, 2026 | CVE Modified | [email protected] |
| Jun 29, 2026 | CVE Modified | [email protected] |
| Jun 26, 2026 | CVE Modified | [email protected] |
| Jun 25, 2026 | CVE Modified | [email protected] |
| Jun 24, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 8, 2026 | Initial Analysis | [email protected] |
| Jun 2, 2026 | CVE Modified | [email protected] |
| Jun 1, 2026 | CVE Modified | [email protected] |
| May 27, 2026 | CVE Modified | [email protected] |
| May 24, 2026 | CVE Modified | [email protected] |
| May 18, 2026 | New CVE Received | [email protected] |