CVE detail
CVE-2026-42014
A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
19 source links · newest first
Information published.
vendormsrc.microsoft.comJun 19, 2026, 8:01 AM- https://access.redhat.com/errata/RHSA-2026:43575access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 16, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:41921access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 16, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:13274access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 16, 2026, 2:16 AM No excerpt available.
referencewww.gnutls.orgJun 16, 2026, 2:16 AMNo excerpt available.
Exploitgitlab.comJun 16, 2026, 2:16 AM- https://bugzilla.redhat.com/show_bug.cgi?id=2467451bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comJun 16, 2026, 2:16 AM - https://access.redhat.com/security/cve/CVE-2026-42014access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 16, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:33125access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 16, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:32962access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 16, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:30850access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 16, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:30849access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 16, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:30004access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 16, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:29197access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 16, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:26409access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 16, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:26319access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 16, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:20613access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 16, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:20612access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 16, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:20611access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 16, 2026, 2:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-17523CVSS 7.8 · High
A flaw was found in the kernel. An unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation…
- CVE-2026-10671CVSS 7.1 · High
In Zephyr's kernel pipe implementation, the userspace syscall verifier z_vrfy_k_pipe_init() in kernel/pipe.c used K_SYSCALL_OBJ() (which requires the kernel object to already be i…
- CVE-2026-54778CVSS 6.2 · Medium
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF UnixDomainSocket POSIX peer identity resolution use…
- CVE-2026-58592CVSS 8.9 · High
Ladybird contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module loader. When a JavaScript function is imported into a WebAssembly module via th…
- CVE-2026-12610CVSS 6.4 · Medium
A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled…
- CVE-2026-57435CVSS 1.7 · Low
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri’s CRuby native extension could leave a Ruby wrapper pointing to freed…