7.5
CVE-2026-42009
- EPSS 1.34%
- Veröffentlicht 18.05.2026 12:44:45
- Zuletzt bearbeitet 02.10.2026 03:16:43
- Erkennungen
Gnutls: gnutls: denial of service via dtls packet reordering vulnerability
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Hardened Images Version -
Redhat ≫ Openshift Container Platform Version 4.0
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0 HwPlatform arm64
Redhat ≫ Enterprise Linux Version 8.0 HwPlatform x64
Redhat ≫ Enterprise Linux For Els Version 8.10 HwPlatform arm64
Redhat ≫ Enterprise Linux For Els Version 8.10 HwPlatform x64
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 8.0_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Els Version 8.10
Redhat ≫ Enterprise Linux For Power Little Endian Version 8.0_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Els Version 8.10
Redhat ≫ Enterprise Linux Version 9.0 HwPlatform arm64
Redhat ≫ Enterprise Linux Version 9.0 HwPlatform x64
Redhat ≫ Enterprise Linux Version 9.8 HwPlatform arm64
Redhat ≫ Enterprise Linux For Els Version 9.8 HwPlatform arm64
Redhat ≫ Enterprise Linux For Els Version 9.8 HwPlatform x64
Redhat ≫ Enterprise Linux For Eus Version 9.8 HwPlatform arm64
Redhat ≫ Enterprise Linux For Eus Version 9.8 HwPlatform x64
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 9.0_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Els Version 9.8
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 9.8
Redhat ≫ Enterprise Linux For Power Little Endian Version 9.0_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Els Version 9.8
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 9.8
Redhat ≫ Enterprise Linux For Update Services For Sap Solutions Version 9.8 HwPlatform x64
Redhat ≫ Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions Version 9.8
Redhat ≫ Enterprise Linux Version 10.0 HwPlatform arm64
Redhat ≫ Enterprise Linux Version 10.0 HwPlatform x64
Redhat ≫ Enterprise Linux Version 10.2 HwPlatform arm64
Redhat ≫ Enterprise Linux Version 10.2 HwPlatform x64
Redhat ≫ Enterprise Linux For Els Version 10.2 HwPlatform arm64
Redhat ≫ Enterprise Linux For Els Version 10.2 HwPlatform x64
Redhat ≫ Enterprise Linux For Eus Version 10.2 HwPlatform arm64
Redhat ≫ Enterprise Linux For Eus Version 10.2 HwPlatform x64
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 9.0_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 10.2
Redhat ≫ Enterprise Linux For Ibm Z Systems Els Version 10.2
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 10.2
Redhat ≫ Enterprise Linux For Power Little Endian Version 10.0
Redhat ≫ Enterprise Linux For Power Little Endian Version 10.2
Redhat ≫ Enterprise Linux For Power Little Endian Els Version 10.2
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 10.2
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.34% | 0.676 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| RedHat | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-475 Undefined Behavior for Input to API
The behavior of this function is undefined unless its control parameter is set to a specific value.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://bugzilla.redhat.com/show_bug.cgi?id=2467279
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42009.json
https://access.redhat.com/errata/RHSA-2026:36004
https://access.redhat.com/errata/RHSA-2026:36005
https://access.redhat.com/errata/RHSA-2026:36006
https://access.redhat.com/errata/RHSA-2026:13274
https://access.redhat.com/errata/RHSA-2026:20611
https://access.redhat.com/errata/RHSA-2026:20612
https://access.redhat.com/errata/RHSA-2026:20613
https://access.redhat.com/errata/RHSA-2026:26319
https://access.redhat.com/errata/RHSA-2026:26409
https://access.redhat.com/errata/RHSA-2026:29197
https://access.redhat.com/errata/RHSA-2026:30004
https://access.redhat.com/errata/RHSA-2026:30849
https://access.redhat.com/errata/RHSA-2026:30850
https://access.redhat.com/errata/RHSA-2026:32962
https://access.redhat.com/errata/RHSA-2026:33125
https://access.redhat.com/errata/RHSA-2026:34372
https://access.redhat.com/errata/RHSA-2026:29794
https://access.redhat.com/security/cve/CVE-2026-42009
https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-2
https://access.redhat.com/errata/RHSA-2026:34764
https://access.redhat.com/errata/RHSA-2026:34788
https://access.redhat.com/errata/RHSA-2026:41921
https://access.redhat.com/errata/RHSA-2026:40762
https://access.redhat.com/errata/RHSA-2026:58981
https://access.redhat.com/errata/RHSA-2026:57483
https://access.redhat.com/errata/RHSA-2026:56786
https://access.redhat.com/errata/RHSA-2026:56853
https://access.redhat.com/errata/RHSA-2026:56911
https://access.redhat.com/errata/RHSA-2026:59831
https://access.redhat.com/errata/RHSA-2026:60019
https://access.redhat.com/errata/RHSA-2026:65839
https://access.redhat.com/errata/RHSA-2026:72502
https://access.redhat.com/errata/RHSA-2026:74674