CVE-2026-42009

7.5 HIGH
Published: May 18, 2026 Modified: June 08, 2026
View on NVD

Description

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:13274
Source: secalert@redhat.com
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:20611
Source: secalert@redhat.com
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:20612
Source: secalert@redhat.com
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:20613
Source: secalert@redhat.com
Third Party Advisory
https://access.redhat.com/security/cve/CVE-2026-42009
Source: secalert@redhat.com
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2467279
Source: secalert@redhat.com
Issue Tracking Third Party Advisory

6 reference(s) from NVD

Quick Stats

CVSS v3 Score
7.5 / 10.0
EPSS (Exploit Probability)
0.8%
52th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

redhat gnu