Always-Incorrect Control Flow Implementation in GnuTLS - CVE-2026-42009
Published: April 30, 2026
GnuTLS
GnuTLS
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper implementation of a qsort comparator contract in the DTLS packet sequence number comparator when ordering DTLS packets by sequence numbers. A remote attacker can send DTLS packets with duplicate sequence numbers to cause a denial of service.