CVE-2026-42009

NameCVE-2026-42009
DescriptionA flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6281-1
Debian Bugs1135319

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gnutls28 (PTS)bullseye3.7.1-5+deb11u5vulnerable
bullseye (security)3.7.1-5+deb11u9vulnerable
bookworm3.7.9-2+deb12u6vulnerable
bookworm (security)3.7.9-2+deb12u7fixed
trixie3.8.9-3+deb13u3vulnerable
trixie (security)3.8.9-3+deb13u4fixed
forky, sid3.8.13-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gnutls28sourcebookworm3.7.9-2+deb12u7DSA-6281-1
gnutls28sourcetrixie3.8.9-3+deb13u4DSA-6281-1
gnutls28source(unstable)3.8.13-11135319

Notes

https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-2
https://gitlab.com/gnutls/gnutls/-/issues/1848
Fixed by: https://gitlab.com/gnutls/gnutls/-/commit/f01e21441e29052a6f0963840794c41d3b3ee66d (3.8.13)
Fixed by: https://gitlab.com/gnutls/gnutls/-/commit/f341441fad91142897d83b44a175ffc8f925b76f (3.8.13)

Search for package or bug name: Reporting problems