CVE-2026-42009 @ Saiph
Package interrogation (copy)
Run on the host — click to copy a command. Debian/apt
| Package | Commands |
|---|---|
| gnutls-deb0-28-3.3.8-6+deb8u6 | |
| gnutls-openssl27-3.6.7-4+deb10u12) | |
| gnutls-deb0-28 | |
| gnutls |
Inventory lookup
Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.
Suggestions: gnutls-deb0 · gnutls-openssl27 · gnutls · gnutls-deb0-28
Same product CVEs in your queue
Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.
| CVE | CVSS | KEV | Systems | Status | Matched | Already related | |
|---|---|---|---|---|---|---|---|
| CVE-2026-33845 | 7.5 | Library, Saiph, morris, mufasa | accepted_risk, does_not_affect | gnutls | — | ||
| CVE-2026-1584 | 7.5 | Library, Saiph, morris, mufasa | new | gnutls | — | ||
| CVE-2026-42010 | 7.1 | Library, Matrix, Saiph, morris, mufasa | not_applicable | gnutls | — |
Related CVE (same fix)
This CVE is subordinated to primary CVE-2026-42010 — same product as CVE-2026-42010
Host OS / kernel
uname -r → 4.19.0-27-amd64uname -v → #1 SMP Debian 4.19.316-1 (2024-06-25)For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.
Same CVE on other hosts
Open the ticket for this CVE on another system.
| System | Status | Priority | Updated | |
|---|---|---|---|---|
| morris | not_applicable | 6.06 | 2026-08-22T10:15:30Z | Open |
| mufasa | not_applicable | 6.06 | 2026-08-22T10:15:30Z | Open |
| Library | not_applicable | 1.47 | 2026-08-22T10:15:30Z | Open |
| Matrix | not_applicable | 1.47 | 2026-08-03T17:04:52Z | Open |
Description
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.
Determination
Related to primary CVE-2026-42010: same product as CVE-2026-42010
Update status
Add note only
Mitigation log
References
- https://access.redhat.com/errata/RHSA-2026:13274
- https://access.redhat.com/errata/RHSA-2026:20611
- https://access.redhat.com/errata/RHSA-2026:20612
- https://access.redhat.com/errata/RHSA-2026:20613
- https://access.redhat.com/errata/RHSA-2026:26319
- https://access.redhat.com/errata/RHSA-2026:26409
- https://access.redhat.com/errata/RHSA-2026:29197
- https://access.redhat.com/errata/RHSA-2026:29794
- https://access.redhat.com/errata/RHSA-2026:30004
- https://access.redhat.com/errata/RHSA-2026:30849
- https://access.redhat.com/errata/RHSA-2026:30850
- https://access.redhat.com/errata/RHSA-2026:32962
- https://access.redhat.com/errata/RHSA-2026:33125
- https://access.redhat.com/errata/RHSA-2026:34372
- https://access.redhat.com/errata/RHSA-2026:34764
NVD: CVE-2026-42009