CVE-2026-42009
7.5
HIGH
CVSS 3.1
EPSS 0.49%
Description
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.
How to fix CVE-2026-42009
To remediate CVE-2026-42009, upgrade the affected package to a fixed version below.
- —upgrade to 3.8.13-r0 or later
- —upgrade to 3.7.1-5+deb11u10 or later
Is CVE-2026-42009 being exploited?
Low — EPSS is 0.5%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 3.8.13-r0
- from 0, < 3.7.1-5+deb11u10
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |