A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS pa…
High CVSS 7.5
Summary
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
- :
- :
- :
Lint boundary warnings (1)
The following non-blocking warnings were raised during the lint phase of this triage (e.g. reference URLs not yet on the allowlist). They do not affect entry usability and are disclosed for transparency (see DR-002).
-
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-2
Sources
- NVD DATABASE
Original Links
- https://access.redhat.com/errata/RHSA-2026:13274 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:20611 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:20612 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:20613 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:26319
- https://access.redhat.com/errata/RHSA-2026:26409
- https://access.redhat.com/errata/RHSA-2026:29197
- https://access.redhat.com/errata/RHSA-2026:29794
- https://access.redhat.com/errata/RHSA-2026:30004
- https://access.redhat.com/errata/RHSA-2026:30849
- https://access.redhat.com/errata/RHSA-2026:30850
- https://access.redhat.com/errata/RHSA-2026:32962
- https://access.redhat.com/errata/RHSA-2026:33125
- https://access.redhat.com/errata/RHSA-2026:34372
- https://access.redhat.com/errata/RHSA-2026:34764
- https://access.redhat.com/errata/RHSA-2026:34788
- https://access.redhat.com/errata/RHSA-2026:36004
- https://access.redhat.com/errata/RHSA-2026:36005
- https://access.redhat.com/errata/RHSA-2026:36006
- https://access.redhat.com/errata/RHSA-2026:41921
- https://access.redhat.com/security/cve/CVE-2026-42009 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2467279 Issue Tracking
- https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-2
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42009.json
Timeline
- nvd_ingest NVD