Gnutls: gnutls: denial of service via dtls packet reordering vulnerability
Published May 18, 2026
7.5
HIGHCVSS 3.1
EPSS 1.13%
Description
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4 | affected |
|
Configuration 1
- n/a
- n/a
- 4.0
- 6.0
- 7.0
Configuration 2
- 8.0
- 8.0
- 8.10
- 8.10
- 8.0_s390x
- 8.10
- 8.0_ppc64le
- 8.10
Configuration 3
- 9.0
- 9.0
- 9.8
- 9.8
- 9.8
- 9.8
- 9.8
- 9.0_s390x
- 9.8
- 9.8
- 9.0_ppc64le
- 9.8
- 9.8
- 9.8
- 9.8
Configuration 4
- 10.0
- 10.0
- 10.2
- 10.2
- 10.2
- 10.2
- 10.2
- 10.2
- 9.0_s390x
- 10.2
- 10.2
- 10.2
- 10.0
- 10.2
- 10.2
- 10.2
No data.
Red Hat AI Inference Server 3.2
rhaiis/model-opt-cuda-rhel9:1782951051
Fixed · RHSA-2026:36004
Red Hat AI Inference Server 3.2
rhaiis/vllm-cuda-rhel9:1782951012
Fixed · RHSA-2026:36005
Red Hat AI Inference Server 3.2
rhaiis/vllm-rocm-rhel9:1782951244
Fixed · RHSA-2026:36006
Red Hat Discovery 2
discovery/discovery-server-rhel9:1782159791
Fixed · RHSA-2026:29197
Red Hat Discovery 2
discovery/discovery-ui-rhel9:1782166952
Fixed · RHSA-2026:29197
Red Hat Enterprise Linux 10
gnutls-0:3.8.10-4.el10_2
Fixed · RHSA-2026:20613
Red Hat Enterprise Linux 10.0 Extended Update Support
gnutls-0:3.8.9-9.el10_0.19
Fixed · RHSA-2026:26409
Red Hat Enterprise Linux 7 Extended Lifecycle Support
gnutls-0:3.3.29-9.el7_9.1
Fixed · RHSA-2026:34372
Red Hat Enterprise Linux 8
gnutls-0:3.6.16-8.el8_10.6
Fixed · RHSA-2026:20611
Red Hat Enterprise Linux 8
gnutls-0:3.6.16-8.el8_10.6
Fixed · RHSA-2026:20611
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
gnutls-0:3.6.14-10.el8_4.1
Fixed · RHSA-2026:33125
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
libtasn1-0:4.13-3.el8_4.1
Fixed · RHSA-2026:33125
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
gnutls-0:3.6.14-10.el8_4.1
Fixed · RHSA-2026:33125
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
libtasn1-0:4.13-3.el8_4.1
Fixed · RHSA-2026:33125
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
gnutls-0:3.6.16-5.el8_6.5
Fixed · RHSA-2026:30849
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
libtasn1-0:4.13-3.el8_6.2
Fixed · RHSA-2026:30849
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
gnutls-0:3.6.16-5.el8_6.5
Fixed · RHSA-2026:30849
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
libtasn1-0:4.13-3.el8_6.2
Fixed · RHSA-2026:30849
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
gnutls-0:3.6.16-7.el8_8.4
Fixed · RHSA-2026:30850
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
libtasn1-0:4.13-4.el8_8.1
Fixed · RHSA-2026:30850
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
gnutls-0:3.6.16-7.el8_8.4
Fixed · RHSA-2026:30850
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
libtasn1-0:4.13-4.el8_8.1
Fixed · RHSA-2026:30850
Red Hat Enterprise Linux 9
gnutls-0:3.8.10-4.el9_8
Fixed · RHSA-2026:20612
Red Hat Enterprise Linux 9
gnutls-0:3.8.10-4.el9_8
Fixed · RHSA-2026:20612
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
gnutls-0:3.7.6-21.el9_2.7
Fixed · RHSA-2026:41921
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
gnutls-0:3.8.3-4.el9_4.6
Fixed · RHSA-2026:32962
Red Hat Enterprise Linux 9.6 Extended Update Support
gnutls-0:3.8.3-6.el9_6.4
Fixed · RHSA-2026:30004
Red Hat Hardened Images
gnutls-main-3.8.13-1.hum1
Fixed · RHSA-2026:13274
Red Hat OpenShift Container Platform 4.12
rhcos-412.86.202608241157-0
Fixed · RHSA-2026:59831
Red Hat OpenShift Container Platform 4.13
rhcos-413.92.202609080414-0
Fixed · RHSA-2026:65839
Red Hat OpenShift Container Platform 4.14
rhcos-414.92.202608172040-0
Fixed · RHSA-2026:56786
Red Hat OpenShift Container Platform 4.15
rhcos-415.92.202608180329-0
Fixed · RHSA-2026:56911
Red Hat OpenShift Container Platform 4.16
rhcos-416.94.202608150307-0
Fixed · RHSA-2026:56853
Red Hat OpenShift Container Platform 4.17
rhcos-417.94.202608250221-0
Fixed · RHSA-2026:60019
Red Hat OpenShift Container Platform 4.18
rhcos-418.94.202608142238-0
Fixed · RHSA-2026:57483
Red Hat OpenShift Container Platform 4.19
rhcos-4.19.9.6.202607151909-0
Fixed · RHSA-2026:40762
Red Hat OpenShift Container Platform 4.20
rhcos-4.20.9.6.202607010620-0
Fixed · RHSA-2026:34788
Red Hat OpenShift Container Platform 4.21
rhcos-4.21.9.6.202607011303-0
Fixed · RHSA-2026:34764
Red Hat OpenShift Container Platform 4.22
rhcos-4.22.9.8.202606230855-0
Fixed · RHSA-2026:29794
Red Hat Update Infrastructure 5
rhui5/cds-kubernetes-tp-rhel9:1787241211
Fixed · RHSA-2026:58981
Red Hat Update Infrastructure 5
rhui5/cds-rhel9:1781525684
Fixed · RHSA-2026:26319
Red Hat Update Infrastructure 5
rhui5/haproxy-rhel9:1781525671
Fixed · RHSA-2026:26319
Red Hat Update Infrastructure 5
rhui5/installer-rhel9:1781525693
Fixed · RHSA-2026:26319
Red Hat Update Infrastructure 5
rhui5/installer-tp-rhel9:1787135742
Fixed · RHSA-2026:58981
Red Hat Update Infrastructure 5
rhui5/rhua-rhel9:1781525739
Fixed · RHSA-2026:26319
Red Hat Update Infrastructure 5
rhui5/rhua-tp-rhel9:1787241260
Fixed · RHSA-2026:58981
Red Hat Enterprise Linux 6
gnutls
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat AI Inference Server 3.2 | rhaiis/model-opt-cuda-rhel9:1782951051 | Fixed | RHSA-2026:36004 |
| Red Hat AI Inference Server 3.2 | rhaiis/vllm-cuda-rhel9:1782951012 | Fixed | RHSA-2026:36005 |
| Red Hat AI Inference Server 3.2 | rhaiis/vllm-rocm-rhel9:1782951244 | Fixed | RHSA-2026:36006 |
| Red Hat Discovery 2 | discovery/discovery-server-rhel9:1782159791 | Fixed | RHSA-2026:29197 |
| Red Hat Discovery 2 | discovery/discovery-ui-rhel9:1782166952 | Fixed | RHSA-2026:29197 |
| Red Hat Enterprise Linux 10 | gnutls-0:3.8.10-4.el10_2 | Fixed | RHSA-2026:20613 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | gnutls-0:3.8.9-9.el10_0.19 | Fixed | RHSA-2026:26409 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | gnutls-0:3.3.29-9.el7_9.1 | Fixed | RHSA-2026:34372 |
| Red Hat Enterprise Linux 8 | gnutls-0:3.6.16-8.el8_10.6 | Fixed | RHSA-2026:20611 |
| Red Hat Enterprise Linux 8 | gnutls-0:3.6.16-8.el8_10.6 | Fixed | RHSA-2026:20611 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | gnutls-0:3.6.14-10.el8_4.1 | Fixed | RHSA-2026:33125 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | libtasn1-0:4.13-3.el8_4.1 | Fixed | RHSA-2026:33125 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | gnutls-0:3.6.14-10.el8_4.1 | Fixed | RHSA-2026:33125 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | libtasn1-0:4.13-3.el8_4.1 | Fixed | RHSA-2026:33125 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | gnutls-0:3.6.16-5.el8_6.5 | Fixed | RHSA-2026:30849 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | libtasn1-0:4.13-3.el8_6.2 | Fixed | RHSA-2026:30849 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | gnutls-0:3.6.16-5.el8_6.5 | Fixed | RHSA-2026:30849 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | libtasn1-0:4.13-3.el8_6.2 | Fixed | RHSA-2026:30849 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | gnutls-0:3.6.16-7.el8_8.4 | Fixed | RHSA-2026:30850 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | libtasn1-0:4.13-4.el8_8.1 | Fixed | RHSA-2026:30850 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | gnutls-0:3.6.16-7.el8_8.4 | Fixed | RHSA-2026:30850 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | libtasn1-0:4.13-4.el8_8.1 | Fixed | RHSA-2026:30850 |
| Red Hat Enterprise Linux 9 | gnutls-0:3.8.10-4.el9_8 | Fixed | RHSA-2026:20612 |
| Red Hat Enterprise Linux 9 | gnutls-0:3.8.10-4.el9_8 | Fixed | RHSA-2026:20612 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | gnutls-0:3.7.6-21.el9_2.7 | Fixed | RHSA-2026:41921 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | gnutls-0:3.8.3-4.el9_4.6 | Fixed | RHSA-2026:32962 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | gnutls-0:3.8.3-6.el9_6.4 | Fixed | RHSA-2026:30004 |
| Red Hat Hardened Images | gnutls-main-3.8.13-1.hum1 | Fixed | RHSA-2026:13274 |
| Red Hat OpenShift Container Platform 4.12 | rhcos-412.86.202608241157-0 | Fixed | RHSA-2026:59831 |
| Red Hat OpenShift Container Platform 4.13 | rhcos-413.92.202609080414-0 | Fixed | RHSA-2026:65839 |
| Red Hat OpenShift Container Platform 4.14 | rhcos-414.92.202608172040-0 | Fixed | RHSA-2026:56786 |
| Red Hat OpenShift Container Platform 4.15 | rhcos-415.92.202608180329-0 | Fixed | RHSA-2026:56911 |
| Red Hat OpenShift Container Platform 4.16 | rhcos-416.94.202608150307-0 | Fixed | RHSA-2026:56853 |
| Red Hat OpenShift Container Platform 4.17 | rhcos-417.94.202608250221-0 | Fixed | RHSA-2026:60019 |
| Red Hat OpenShift Container Platform 4.18 | rhcos-418.94.202608142238-0 | Fixed | RHSA-2026:57483 |
| Red Hat OpenShift Container Platform 4.19 | rhcos-4.19.9.6.202607151909-0 | Fixed | RHSA-2026:40762 |
| Red Hat OpenShift Container Platform 4.20 | rhcos-4.20.9.6.202607010620-0 | Fixed | RHSA-2026:34788 |
| Red Hat OpenShift Container Platform 4.21 | rhcos-4.21.9.6.202607011303-0 | Fixed | RHSA-2026:34764 |
| Red Hat OpenShift Container Platform 4.22 | rhcos-4.22.9.8.202606230855-0 | Fixed | RHSA-2026:29794 |
| Red Hat Update Infrastructure 5 | rhui5/cds-kubernetes-tp-rhel9:1787241211 | Fixed | RHSA-2026:58981 |
| Red Hat Update Infrastructure 5 | rhui5/cds-rhel9:1781525684 | Fixed | RHSA-2026:26319 |
| Red Hat Update Infrastructure 5 | rhui5/haproxy-rhel9:1781525671 | Fixed | RHSA-2026:26319 |
| Red Hat Update Infrastructure 5 | rhui5/installer-rhel9:1781525693 | Fixed | RHSA-2026:26319 |
| Red Hat Update Infrastructure 5 | rhui5/installer-tp-rhel9:1787135742 | Fixed | RHSA-2026:58981 |
| Red Hat Update Infrastructure 5 | rhui5/rhua-rhel9:1781525739 | Fixed | RHSA-2026:26319 |
| Red Hat Update Infrastructure 5 | rhui5/rhua-tp-rhel9:1787241260 | Fixed | RHSA-2026:58981 |
| Red Hat Enterprise Linux 6 | gnutls | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The impact for this flaw has been downgraded on Red Hat Enterprise Linux due to the following reason: - The number of elements passed to the vulnerable function at runtime is known and is at most 6 and the element size is sufficiently small. glibc’s qsort implementation will not exercise the quick sort code path, which would otherwise cause an infloop or out-of-bound write.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed May 18, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
May–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.13% (0.01129) | 65.16th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.78% (0.00783) | 51.04th | v5 (v2026.06.15) |
| May 19, 2026 | 0.12% (0.00123) | 30.89th | v4 (v2025.03.14) |
References (37)
- https://access.redhat.com/errata/RHSA-2026:13274 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:20611 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:20612 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:20613 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:26319 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:26409 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:29197 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:29794 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:30004 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:30849 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:30850 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:32962 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:33125 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:34372 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:34764 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:34788 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:36004 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:36005 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:36006 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:40762 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:41921 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:56786 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:56853 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:56911 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:57483 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:58981 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:59831 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:60019 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:65839 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:72502 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74674 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-42009 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2467279 issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-42009
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42009.json
- https://www.cve.org/CVERecord?id=CVE-2026-42009
- https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-2
Change history (0)
No recorded changes yet.