ALPINE-CVE-2026-42009

Source
https://security.alpinelinux.org/vuln/CVE-2026-42009
Import Source
https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2026-42009.json
JSON Data
https://api.osv.dev/v1/vulns/ALPINE-CVE-2026-42009
Upstream
  • CVE-2026-42009
Published
2026-05-18T13:16:32.707Z
Modified
2026-06-15T18:18:11.227863083Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.

References

Affected packages

Alpine:v3.20 / gnutls

Package

Name
gnutls
Purl
pkg:apk/alpine/gnutls?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.8.13-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2026-42009.json"

Alpine:v3.21 / gnutls

Package

Name
gnutls
Purl
pkg:apk/alpine/gnutls?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.8.13-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2026-42009.json"

Alpine:v3.22 / gnutls

Package

Name
gnutls
Purl
pkg:apk/alpine/gnutls?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.8.13-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2026-42009.json"

Alpine:v3.23 / gnutls

Package

Name
gnutls
Purl
pkg:apk/alpine/gnutls?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.8.13-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2026-42009.json"

Alpine:v3.24 / gnutls

Package

Name
gnutls
Purl
pkg:apk/alpine/gnutls?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.8.13-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2026-42009.json"