CVE-2026-42009: GNU Gnutls
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.
Affected products
- GNU Gnutls: affected versions not specified
- Red Hat Enterprise Linux: version 6.0 only; version 7.0 only; version 8.0 only; version 9.0 only; version 9.8 only; version 10.0 only; …
- Red Hat Enterprise Linux For Els: version 8.10 only; version 9.8 only; version 10.2 only
- Red Hat Enterprise Linux For Eus: version 9.8 only; version 10.2 only
- Red Hat Enterprise Linux For IBM Z Systems: version 8.0_s390x only; version 9.0_s390x only; version 10.2 only
- Red Hat Enterprise Linux For IBM Z Systems Els: version 8.10 only; version 9.8 only; version 10.2 only
- Red Hat Enterprise Linux For IBM Z Systems Eus: version 9.8 only; version 10.2 only
- Red Hat Enterprise Linux For Power Little Endian: version 8.0_ppc64le only; version 9.0_ppc64le only; version 10.0 only; version 10.2 only
- Red Hat Enterprise Linux For Power Little Endian Els: version 8.10 only; version 9.8 only; version 10.2 only
- Red Hat Enterprise Linux For Power Little Endian Eus: version 9.8 only; version 10.2 only
- Red Hat Enterprise Linux For Update Services For SAP Solutions: version 9.8 only
- Red Hat Enterprise Linux Server For Power Little Endian Update Services For SAP Solutions: version 9.8 only
- Red Hat Hardened Images: affected versions not specified
- Red Hat Openshift Container Platform: version 4.0 only
Published 2026-05-18. Last modified 2026-10-08.