Use-after-free in GnuTLS - CVE-2026-42014
Published: April 30, 2026
GnuTLS
GnuTLS
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in gnutls_pkcs11_token_set_pin() when changing the Security Officer PIN with oldpin set to NULL for a token lacking a protected authentication path. A remote attacker can trigger the vulnerable function call to cause a denial of service.