Back

HIGH

Gnutls: gnutls: denial of service via dtls packet reordering vulnerability

Published May 18, 2026

Description

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.

Affected products

Remediation

Red Hat statement

The impact for this flaw has been downgraded on Red Hat Enterprise Linux due to the following reason: - The number of elements passed to the vulnerable function at runtime is known and is at most 6 and the element size is sufficiently small. glibc’s qsort implementation will not exercise the quick sort code path, which would otherwise cause an infloop or out-of-bound write.

Metrics

Weaknesses (1)

References (37)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 18, 2026
Updated Oct 2, 2026
Reserved Apr 23, 2026
CISA Vulnrichment
Updated May 18, 2026
NVD
Status Modified
Modified Oct 2, 2026
Red Hat
Severity Important
Public date Apr 29, 2026