Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42014

Опубликовано: 29 апр. 2026
Источник: redhat
CVSS3: 6.6

Описание

A flaw was found in GnuTLS. The gnutls_pkcs11_token_set_pin function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gnutlsOut of support scope
Red Hat Enterprise Linux 7gnutlsAffected
Red Hat OpenShift Container Platform 4openshift4/ose-hypershift-rhel9Under investigation
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Enterprise Linux 10gnutlsFixedRHSA-2026:2061326.05.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportgnutlsFixedRHSA-2026:2640916.06.2026
Red Hat Enterprise Linux 8gnutlsFixedRHSA-2026:2061126.05.2026
Red Hat Enterprise Linux 8gnutlsFixedRHSA-2026:2061126.05.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportgnutlsFixedRHSA-2026:3312529.06.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportlibtasn1FixedRHSA-2026:3312529.06.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2467451gnutls: gnutls: Use-after-free in gnutls_pkcs11_token_set_pin

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.6
ubuntu
около 2 месяцев назад

A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.

CVSS3: 6.6
nvd
около 2 месяцев назад

A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.

msrc
около 1 месяца назад

Gnutls: fix use-after-free in gnutls_pkcs11_token_set_pin

CVSS3: 6.6
debian
около 2 месяцев назад

A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function ...

suse-cvrf
16 дней назад

Security update for gnutls

6.6 Medium

CVSS3