CVE-2026-42009

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.
Configurations

No configuration.

History

02 Jun 2026, 16:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:20612 -

01 Jun 2026, 21:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:20613 -

27 May 2026, 04:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:20611 -

24 May 2026, 02:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:13274 -

18 May 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-18 13:16

Updated : 2026-06-02 16:16


NVD link : CVE-2026-42009

Mitre link : CVE-2026-42009

CVE.ORG link : CVE-2026-42009


JSON object : View

Products Affected

No product.

CWE
CWE-475

Undefined Behavior for Input to API