← All Advisories

CVE-2026-42009

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-42009

Key Details

CVECVE-2026-42009
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-10-02
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productssee table below
Classified asCWE-475 (Undefined Behavior for Input to API)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatEnterprise Linux
Red HatOpenShift Container Platform
Red Hathardened_images
Red HatRed Hat OpenShift AI 3.4
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
Red HatRed Hat Update Infrastructure 5
Red HatRed Hat Hardened Images
Red HatRed Hat OpenShift Container Platform 4.12
Red HatRed Hat OpenShift Container Platform 4.13
Red HatRed Hat OpenShift Container Platform 4.14
Red HatRed Hat OpenShift Container Platform 4.15
Red HatRed Hat OpenShift Container Platform 4.16
Red HatRed Hat OpenShift Container Platform 4.17
Red HatRed Hat OpenShift Container Platform 4.18
Red HatRed Hat OpenShift Container Platform 4.19
Red HatRed Hat OpenShift Container Platform 4
Red HatRed Hat OpenShift Container Platform 4.20
Red HatRed Hat OpenShift Container Platform 4.21
Red HatRed Hat OpenShift Container Platform 4.22
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support
gnugnutls
Red HatCert Manager support for Red Hat OpenShift release 1.20
Red HatRed Hat AI Inference Server 3.2
Red HatRed Hat Discovery 2
Red Hatenterprise_linux_for_els
Red Hatenterprise_linux_for_ibm_z_systems
Red Hatenterprise_linux_for_ibm_z_systems_els
Red Hatenterprise_linux_for_power_little_endian
Red Hatenterprise_linux_for_power_little_endian_els
Red Hatenterprise_linux_for_eus
Red Hatenterprise_linux_for_ibm_z_systems_eus
Red Hatenterprise_linux_for_power_little_endian_eus
Red Hatenterprise_linux_for_update_services_for_sap_solutions
Red Hatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions
SubsystemsCore Infrastructure, EWS Workstation Delivery/Virtualization
SectorsAll Sectors

What to Know

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service. (NVD)

What to Do

Monitor Red Hat's and gnu's web pages for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-42009
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-42009