A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.
References
Configurations
No configuration.
History
22 Jul 2026, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
20 Jul 2026, 12:19
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
15 Jul 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
30 Jun 2026, 03:19
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
29 Jun 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
29 Jun 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
26 Jun 2026, 08:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
24 Jun 2026, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
17 Jun 2026, 13:20
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
16 Jun 2026, 02:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-16 02:16
Updated : 2026-07-22 16:17
NVD link : CVE-2026-42014
Mitre link : CVE-2026-42014
CVE.ORG link : CVE-2026-42014
JSON object : View
Products Affected
No product.
CWE
CWE-825
Expired Pointer Dereference
