CVE Tracker

CVE-2026-42009 @ Matrix

Status
not_applicable
Priority
1.47
Match score
3.0
Risk
DoS Remote
CVSS
7.5 HIGH
Reason
cpe: gnutls; pkgs: gnutls-dane0; version: unknown (gnutls-dane0-3.7.9-2+deb12u7); risk:dos
Created
2026-08-03T03:52:11Z
Updated
2026-08-03T17:04:52Z
Closed
2026-08-03T03:57:46Z

Package interrogation (copy)

Run on the host — click to copy a command. Debian/apt

PackageCommands
gnutls-dane0-3.7.9-2+deb12u7)
gnutls

Inventory lookup

Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.

Clear

Suggestions: gnutls-dane0 · gnutls

SystemMatchesTicket for CVE-2026-42009
Library libcurl3-gnutls 7.52.1-5+deb9u16; libgnutls-deb0-28 3.3.8-6+deb8u7; libgnutls-openssl27 3.5.8-5+deb9u6; libgnutls30 3.5.8-5+deb9u6 not_applicable open
Matrix libcurl3-gnutls 7.88.1-10+deb12u15; libgnutls-dane0 3.7.9-2+deb12u7; libgnutls30 3.7.9-2+deb12u7 not_applicable open
Saiph libcurl3-gnutls 7.64.0-4+deb10u9; libgnutls-deb0-28 3.3.8-6+deb8u6; libgnutls-openssl27 3.6.7-4+deb10u12; libgnutls30 3.6.7-4+deb10u12 not_applicable open
morris gnutls 3.3.29 not_applicable open
mufasa gnutls 3.3.29 not_applicable open
Archive libgnutls30 3.6.7-4+deb10u12 none
Bullseye libcurl3-gnutls 7.74.0-1.3+deb11u16; libgnutls30 3.7.1-5+deb11u10 none
Helios libcurl3-gnutls 7.74.0-1.3+deb11u16; libgnutls30 3.7.1-5+deb11u10 none
Janus libcurl3-gnutls 7.64.0-4+deb10u9; libgnutls30 3.6.7-4+deb10u12 none
Silk libcurl3-gnutls 7.88.1-10+deb12u15; libgnutls30 3.7.9-2+deb12u7 none

Same product CVEs in your queue

Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.

CVECVSSKEVSystemsStatus MatchedAlready related
CVE-2026-33845 7.5 Library, Saiph, morris, mufasa accepted_risk, does_not_affect gnutls
CVE-2026-1584 7.5 Library, Saiph, morris, mufasa new gnutls
CVE-2026-42010 7.1 Library, Matrix, Saiph, morris, mufasa not_applicable gnutls

Related CVE (same fix)

This CVE is subordinated to primary CVE-2026-42010 — same product as CVE-2026-42010

Host OS / kernel

OS
Debian GNU/Linux 12 (bookworm) (12) · debian
Arch
x86_64
kernel_release
uname -r → 6.1.0-52-amd64
kernel_version
uname -v → #1 SMP PREEMPT_DYNAMIC Debian 6.1.180-1 (2026-08-03)

For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.

Same CVE on other hosts

Open the ticket for this CVE on another system.

System Status Priority Updated
morris not_applicable 6.06 2026-08-22T10:15:30Z Open
mufasa not_applicable 6.06 2026-08-22T10:15:30Z Open
Library not_applicable 1.47 2026-08-22T10:15:30Z Open
Saiph not_applicable 0.48 2026-08-22T10:15:30Z Open

Description

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.

Determination

Related to primary CVE-2026-42010: same product as CVE-2026-42010

Update status

Also apply to other systems with this CVE:

Add note only

Also add note on:

Mitigation log

2026-08-03T03:57:46Z — not_applicable
Related to primary CVE-2026-42010: same product as CVE-2026-42010

References

NVD: CVE-2026-42009