CVE detail
CVE-2026-42009
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
26 source links · newest first
- CVE-2026-42009 Gnutls: gnutls: denial of service via dtls packet reordering vulnerabilityMicrosoft MSRC
Information published.
vendormsrc.microsoft.comMay 23, 2026, 8:01 AM - https://access.redhat.com/errata/RHSA-2026:40762access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 18, 2026, 1:16 PM - https://access.redhat.com/errata/RHSA-2026:41921access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 18, 2026, 1:16 PM - https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42009.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comMay 18, 2026, 1:16 PM No excerpt available.
referencewww.gnutls.orgMay 18, 2026, 1:16 PM- https://bugzilla.redhat.com/show_bug.cgi?id=2467279bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMay 18, 2026, 1:16 PM - https://access.redhat.com/security/cve/CVE-2026-42009access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 18, 2026, 1:16 PM - https://access.redhat.com/errata/RHSA-2026:36006access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 18, 2026, 1:16 PM - https://access.redhat.com/errata/RHSA-2026:36005access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 18, 2026, 1:16 PM - https://access.redhat.com/errata/RHSA-2026:36004access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 18, 2026, 1:16 PM - https://access.redhat.com/errata/RHSA-2026:34788access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 18, 2026, 1:16 PM - https://access.redhat.com/errata/RHSA-2026:34764access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 18, 2026, 1:16 PM - https://access.redhat.com/errata/RHSA-2026:34372access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 18, 2026, 1:16 PM - https://access.redhat.com/errata/RHSA-2026:33125access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 18, 2026, 1:16 PM - https://access.redhat.com/errata/RHSA-2026:32962access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 18, 2026, 1:16 PM - https://access.redhat.com/errata/RHSA-2026:30850access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 18, 2026, 1:16 PM - https://access.redhat.com/errata/RHSA-2026:30849access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 18, 2026, 1:16 PM - https://access.redhat.com/errata/RHSA-2026:30004access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 18, 2026, 1:16 PM - https://access.redhat.com/errata/RHSA-2026:29794access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 18, 2026, 1:16 PM - https://access.redhat.com/errata/RHSA-2026:29197access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 18, 2026, 1:16 PM - https://access.redhat.com/errata/RHSA-2026:26409access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 18, 2026, 1:16 PM - https://access.redhat.com/errata/RHSA-2026:26319access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 18, 2026, 1:16 PM - https://access.redhat.com/errata/RHSA-2026:20613access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 18, 2026, 1:16 PM - https://access.redhat.com/errata/RHSA-2026:20612access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 18, 2026, 1:16 PM - https://access.redhat.com/errata/RHSA-2026:20611access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 18, 2026, 1:16 PM - https://access.redhat.com/errata/RHSA-2026:13274access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 18, 2026, 1:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-0193CVSS 7.8 · High
A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is removed, the element can be dea…
- CVE-2025-6021CVSS 7.5 · High
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memor…
- CVE-2024-12088CVSS 6.5 · Medium
A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another sym…
- CVE-2024-12085CVSS 7.5 · High
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a compari…
- CVE-2024-9676CVSS 6.5 · Medium
A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and resul…
- CVE-2024-9675CVSS 7.8 · High
A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in…