Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-87110.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-87110
Upstream
  • CVE-2026-42009
Published
2026-05-18T13:16:32Z
Modified
2026-08-28T17:47:37Z
Summary
CVE-2026-42009 affecting package gnutls for versions less than 3.8.3-11
Details

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.

References

Affected packages

Azure Linux:3 / gnutls

Package

Name
gnutls
Purl
pkg:rpm/azure-linux/gnutls

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.8.3-11

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-87110.json"