CVE-2026-42009
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 1.33%
- CWE
- CWE-475
- Published
- 2026-05-18
- Last modified
- 2026-09-04
Affected products
- Red Hat Red Hat Hardened Images
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support
- Red Hat Red Hat Update Infrastructure 5
- Red Hat Red Hat Update Infrastructure 5
- Red Hat Red Hat Update Infrastructure 5
Weakness type
Related vulnerabilities
- CVE-2026-19311 — Missing Authorization in Execute Monitor API in OpenSearch Alerting Plugin
- CVE-2026-21690 — iccDEV has Type Confusion in CIccTagXmlTagData::ToXml()
- CVE-2025-47866 — An unrestricted file upload vulnerability in a Trend Micro Apex Central widget below version...
- CVE-2025-47865 — A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955...
- CVE-2024-10569 — Zip Bomb Vulnerability in gradio-app/gradio
- CVE-2024-3099 — Denial of Service and Data Model Poisoning via URL Encoding in mlflow/mlflow
- CVE-2024-20380 — ClamAV HTML Parser Denial of Service Vulnerability
- CVE-2023-4874 — Undefined Behavior for Input to API in Mutt