Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42009

Опубликовано: 29 апр. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.

Отчет

The impact for this flaw has been downgraded on Red Hat Enterprise Linux due to the following reason:

  • The number of elements passed to the vulnerable function at runtime is known and is at most 6 and the element size is sufficiently small. glibc’s qsort implementation will not exercise the quick sort code path, which would otherwise cause an infloop or out-of-bound write.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gnutlsNot affected
Red Hat OpenShift Container Platform 4rhcosAffected
Red Hat Enterprise Linux 10gnutlsFixedRHSA-2026:2061326.05.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportgnutlsFixedRHSA-2026:2640916.06.2026
Red Hat Enterprise Linux 7 Extended Lifecycle SupportgnutlsFixedRHSA-2026:3437201.07.2026
Red Hat Enterprise Linux 8gnutlsFixedRHSA-2026:2061126.05.2026
Red Hat Enterprise Linux 8gnutlsFixedRHSA-2026:2061126.05.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportgnutlsFixedRHSA-2026:3312529.06.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportlibtasn1FixedRHSA-2026:3312529.06.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OngnutlsFixedRHSA-2026:3312529.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-475
https://bugzilla.redhat.com/show_bug.cgi?id=2467279gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability

EPSS

Процентиль: 68%
0.01335
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.

CVSS3: 7.5
nvd
2 месяца назад

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.

CVSS3: 7.5
msrc
2 месяца назад

Gnutls: gnutls: denial of service via dtls packet reordering vulnerability

CVSS3: 7.5
debian
2 месяца назад

A flaw was found in gnutls. A remote attacker could exploit an issue i ...

CVSS3: 7.5
redos
около 1 месяца назад

Уязвимость gnutls

EPSS

Процентиль: 68%
0.01335
Низкий

7.5 High

CVSS3