Back

MEDIUM

Gnutls: gnutls: use-after-free in gnutls_pkcs11_token_set_pin

Published Jun 16, 2026

Description

A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (23)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 16, 2026
Updated Oct 2, 2026
Reserved Apr 23, 2026
CISA Vulnrichment
Updated Jun 16, 2026
NVD
Status Awaiting Analysis
Modified Oct 2, 2026
Red Hat
Severity Moderate
Public date Apr 29, 2026