← All Advisories

CVE-2026-42010

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-42010

Key Details

CVECVE-2026-42010
CVSS Score / Version7.1 (High) / CVSS v3.1
Updated2026-10-02
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is low; availability impact is none.
Affected productssee table below
Classified asCWE-170 (Improper Null Termination)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatEnterprise Linux
Red HatOpenShift Container Platform
Red Hathardened_images
Red HatRed Hat OpenShift AI 3.4
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
Red HatRed Hat Update Infrastructure 5
Red HatRed Hat Hardened Images
Red HatRed Hat OpenShift Container Platform 4.12
Red HatRed Hat OpenShift Container Platform 4.13
Red HatRed Hat OpenShift Container Platform 4.14
Red HatRed Hat OpenShift Container Platform 4.15
Red HatRed Hat OpenShift Container Platform 4.16
Red HatRed Hat OpenShift Container Platform 4.17
Red HatRed Hat OpenShift Container Platform 4.18
Red HatRed Hat OpenShift Container Platform 4.19
Red HatRed Hat OpenShift Container Platform 4
Red HatRed Hat OpenShift Container Platform 4.20
Red HatRed Hat OpenShift Container Platform 4.21
Red HatRed Hat OpenShift Container Platform 4.22
gnugnutls
Red HatCert Manager support for Red Hat OpenShift release 1.20
Red HatRed Hat AI Inference Server 3.2
Red HatRed Hat Discovery 2
SubsystemsCore Infrastructure, EWS Workstation Delivery/Virtualization
SectorsAll Sectors

What to Know

A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process. (NVD)

What to Do

Monitor Red Hat's and gnu's web pages for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-42010
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-42010
Vendor advisoryhttps://access.redhat.com/security/cve/CVE-2026-42010