CVE-2026-42014
GnuTLS vulnerability analysis and mitigation

Overview

CVE-2026-42014 is a use-after-free vulnerability in GnuTLS affecting the gnutls_pkcs11_token_set_pin function, which is used for changing the Security Officer PIN on PKCS#11 tokens. The flaw is triggered when an attacker attempts to change the PIN with a NULL old PIN value for a token that lacks a protected authentication path. It affects GnuTLS as packaged across Red Hat Enterprise Linux 8, 9, and 10, as well as Debian, Ubuntu, SUSE, Alpine, and Amazon Linux 2023. The vulnerability was published on June 16, 2026, and carries a CVSS v3.1 base score of 6.6 (Medium/High) (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-825 (Expired Pointer Dereference) by NVD, with an estimated classification of CWE-416 (Use After Free) by Feedly. The vulnerability exists in the gnutls_pkcs11_token_set_pin function: when oldpin is passed as NULL for a PKCS#11 token that does not implement a protected authentication path, the function accesses memory that has already been freed, leading to a use-after-free condition. Exploitation requires local access with low privileges and no user interaction, and is not automatable according to NVD SSVC assessment (GitHub Advisory, Red Hat Bugzilla, GnuTLS Security).

Impact

Successful exploitation by a local low-privileged user can result in a process crash (denial of service) or memory corruption, with potential for limited confidentiality and integrity impact. The CVSS scoring reflects high availability impact, low confidentiality impact, and low integrity impact, all within an unchanged scope. In the worst case, memory corruption could be leveraged for local code execution, though no such exploitation has been demonstrated publicly (GitHub Advisory, Red Hat CVE).

Mitigation and workarounds

Red Hat has released patched packages across multiple RHEL versions: gnutls-3.6.16-8.el8_10.6 for RHEL 8, gnutls-3.8.10-4.el9_8 for RHEL 9, and gnutls-3.8.10-4.el10_2 for RHEL 10, all issued on May 26, 2026 via RHSA-2026:20611, RHSA-2026:20612, and RHSA-2026:20613 respectively (RHSA-2026:20611, RHSA-2026:20612, RHSA-2026:20613). Additional errata were issued for extended update support streams (RHSA-2026:26409, RHSA-2026:30004, RHSA-2026:30849, RHSA-2026:30850, RHSA-2026:32962, RHSA-2026:33125). GnuTLS 3.8.13 upstream also addresses this and related vulnerabilities. As a workaround, restrict access to the gnutls_pkcs11_token_set_pin function to authorized administrators only, and ensure PKCS#11 tokens implement protected authentication paths where possible (GnuTLS Security, Red Hat Bugzilla).

Community reactions

The vulnerability was part of a broader GnuTLS 3.8.13 release that addressed 12 security vulnerabilities, which received coverage from cybersecurity news outlets (CyberSecurityNews). Distribution vendors including Ubuntu (USN-8284-1), SUSE, Debian, openSUSE, and Amazon Linux 2023 issued their own security advisories. Community discussion was limited, consistent with the local-only, low-severity nature of the flaw.

Additional resources


SourceThis report was generated using AI

Related GnuTLS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-5260HIGH8.2
  • GnuTLS logoGnuTLS
  • libtasn1
NoYesMay 26, 2026
CVE-2026-42013HIGH8.2
  • GnuTLS logoGnuTLS
  • libgnutls28
NoYesMay 26, 2026
CVE-2026-42014MEDIUM6.6
  • GnuTLS logoGnuTLS
  • libgnutls-openssl27
NoYesJun 16, 2026
CVE-2026-42015MEDIUM5.3
  • GnuTLS logoGnuTLS
  • gnutls-c++
NoYesMay 26, 2026
CVE-2026-5419LOW3.7
  • GnuTLS logoGnuTLS
  • gnutls-devel
NoYesJun 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management