CVE-2026-42009: Gnutls: gnutls: denial of service via dtls packet reordering vulnerability
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42009?
CVE-2026-42009 has been classified as a moderate severity vulnerability due to its potential to cause denial of service.
How can I fix CVE-2026-42009?
To fix CVE-2026-42009, update GnuTLS to the latest version where the vulnerability has been patched.
What kind of attack is possible with CVE-2026-42009?
CVE-2026-42009 allows remote attackers to exploit a denial of service condition through DTLS packet reordering.
Which software is affected by CVE-2026-42009?
CVE-2026-42009 affects GnuTLS software, specifically versions that utilize Datagram Transport Layer Security.
Is CVE-2026-42009 a widespread vulnerability?
The impact of CVE-2026-42009 may vary, but it primarily affects systems relying on GnuTLS for DTLS functionality.