CVE-2026-42009Disclosure(gnu / enterprise_linux)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-475

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • enterprise_linux_for_els
  • enterprise_linux_for_eus
  • enterprise_linux_for_ibm_z_systems

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-18); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
enterprise_linuxenterprise_linux_for_elsenterprise_linux_for_eusenterprise_linux_for_ibm_z_systemsenterprise_linux_for_ibm_z_systems_elsenterprise_linux_for_ibm_z_systems_eusenterprise_linux_for_power_little_endianenterprise_linux_for_power_little_endian_elsenterprise_linux_for_power_little_endian_eusenterprise_linux_for_update_services_for_sap_solutions

14 versions affected across 14 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-18: 1Mentions · 2026-05-27: 1Technical Details · 2026-05-27: 105-1805-27
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    صدرت اليوم ٨ ثغرات بتصنيف حرج او عالي الخطورة في مكتبة GnuTLS الي شرحتها في التغريده المقتبسه ـ📍 (CVE-2026-42010) تقييم (NVD): 🔴 9.8 (حرجة) تقييم (Red Hat): 🟠 7.1 (عالية) ـ📍 (CVE-2026-33845) تقييم (NVD): 🔴 9.1 (حرجة) تقييم (Red Hat): 🟠 7.5 (عالية) ـ📍 (CVE-2026-42013) تقييم (Red Hat): 🟠 8.2 (عالية) تصنيف (GnuTLS) الرسمي: 🟡 (متوسطة) ـ📍 (CVE-2026-5260) تقييم (Red Hat): 🟠 8.2 (عالية) ـ📍 (CVE-2026-33846) تقييم (Red Hat): 🟠 7.5 (عالية) ـ📍 (CVE-2026-42009) تقييم (Red Hat): 🟠 7.5 (عالية) ـ📍 (CVE-2026-3833) تقييم (NVD): 🟠 7.4 (عالية) تقييم (Red Hat): 🟡 6.5 (متوسطة) ـ📍 (CVE-2026-42011) تقييم (Red Hat / Ubuntu CVSS): 🟠 7.4 (عالية) أولوية (Ubuntu) الفعلية: 🟡 (متوسطة)

    Post summary

    The tweet lists eight newly disclosed GnuTLS vulnerabilities, providing their CVE identifiers and CVSS severity scores without mentioning proofs of concept, exploits, active attacks, or patches.

    03023124.3K
    50.0K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-42009 📊 Severity: 7.5 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-42009 #CVE-2026-42009 #CVE #High  #CyberSecurity #InfoSec https://t.co/9W2L6Yoaw8

    Post summary

    The tweet announces a new CVE (CVE-2026-42009) with a severity rating of 7.5 and high risk level, but lacks technical details, exploit code, or patch information.

    0001059
    160 followersView on X
CPE platform detail43 entries

43 of 43 entries

PartVendorProductVersionTarget SWTarget HW
Appgnugnutls---
OSredhatenterprise_linux10.0-arm64
OSredhatenterprise_linux10.0-x64
OSredhatenterprise_linux10.2-arm64
OSredhatenterprise_linux10.2-x64
OSredhatenterprise_linux6.0--
OSredhatenterprise_linux7.0--
OSredhatenterprise_linux8.0-arm64
OSredhatenterprise_linux8.0-x64
OSredhatenterprise_linux9.0-arm64
OSredhatenterprise_linux9.0-x64
OSredhatenterprise_linux9.8-arm64
OSredhatenterprise_linux_for_els10.2-arm64
OSredhatenterprise_linux_for_els10.2-x64
OSredhatenterprise_linux_for_els8.10-arm64
OSredhatenterprise_linux_for_els8.10-x64
OSredhatenterprise_linux_for_els9.8-arm64
OSredhatenterprise_linux_for_els9.8-x64
OSredhatenterprise_linux_for_eus10.2-arm64
OSredhatenterprise_linux_for_eus10.2-x64
OSredhatenterprise_linux_for_eus9.8-arm64
OSredhatenterprise_linux_for_eus9.8-x64
OSredhatenterprise_linux_for_ibm_z_systems10.2--
OSredhatenterprise_linux_for_ibm_z_systems8.0_s390x--
OSredhatenterprise_linux_for_ibm_z_systems9.0_s390x--
OSredhatenterprise_linux_for_ibm_z_systems_els10.2--
OSredhatenterprise_linux_for_ibm_z_systems_els8.10--
OSredhatenterprise_linux_for_ibm_z_systems_els9.8--
OSredhatenterprise_linux_for_ibm_z_systems_eus10.2--
OSredhatenterprise_linux_for_ibm_z_systems_eus9.8--
OSredhatenterprise_linux_for_power_little_endian10.0--
OSredhatenterprise_linux_for_power_little_endian10.2--
OSredhatenterprise_linux_for_power_little_endian8.0_ppc64le--
OSredhatenterprise_linux_for_power_little_endian9.0_ppc64le--
OSredhatenterprise_linux_for_power_little_endian_els10.2--
OSredhatenterprise_linux_for_power_little_endian_els8.10--
OSredhatenterprise_linux_for_power_little_endian_els9.8--
OSredhatenterprise_linux_for_power_little_endian_eus10.2--
OSredhatenterprise_linux_for_power_little_endian_eus9.8--
OSredhatenterprise_linux_for_update_services_for_sap_solutions9.8-x64
OSredhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions9.8--
Appredhathardened_images---
Appredhatopenshift_container_platform4.0--

Explore more