
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-42014 is a use-after-free vulnerability in GnuTLS affecting the gnutls_pkcs11_token_set_pin function, which is used for changing the Security Officer PIN on PKCS#11 tokens. The flaw is triggered when an attacker attempts to change the PIN with a NULL old PIN value for a token that lacks a protected authentication path. It affects GnuTLS as packaged across Red Hat Enterprise Linux 8, 9, and 10, as well as Debian, Ubuntu, SUSE, Alpine, and Amazon Linux 2023. The vulnerability was published on June 16, 2026, and carries a CVSS v3.1 base score of 6.6 (Medium/High) (GitHub Advisory, Red Hat CVE).
The root cause is classified as CWE-825 (Expired Pointer Dereference) by NVD, with an estimated classification of CWE-416 (Use After Free) by Feedly. The vulnerability exists in the gnutls_pkcs11_token_set_pin function: when oldpin is passed as NULL for a PKCS#11 token that does not implement a protected authentication path, the function accesses memory that has already been freed, leading to a use-after-free condition. Exploitation requires local access with low privileges and no user interaction, and is not automatable according to NVD SSVC assessment (GitHub Advisory, Red Hat Bugzilla, GnuTLS Security).
Successful exploitation by a local low-privileged user can result in a process crash (denial of service) or memory corruption, with potential for limited confidentiality and integrity impact. The CVSS scoring reflects high availability impact, low confidentiality impact, and low integrity impact, all within an unchanged scope. In the worst case, memory corruption could be leveraged for local code execution, though no such exploitation has been demonstrated publicly (GitHub Advisory, Red Hat CVE).
Red Hat has released patched packages across multiple RHEL versions: gnutls-3.6.16-8.el8_10.6 for RHEL 8, gnutls-3.8.10-4.el9_8 for RHEL 9, and gnutls-3.8.10-4.el10_2 for RHEL 10, all issued on May 26, 2026 via RHSA-2026:20611, RHSA-2026:20612, and RHSA-2026:20613 respectively (RHSA-2026:20611, RHSA-2026:20612, RHSA-2026:20613). Additional errata were issued for extended update support streams (RHSA-2026:26409, RHSA-2026:30004, RHSA-2026:30849, RHSA-2026:30850, RHSA-2026:32962, RHSA-2026:33125). GnuTLS 3.8.13 upstream also addresses this and related vulnerabilities. As a workaround, restrict access to the gnutls_pkcs11_token_set_pin function to authorized administrators only, and ensure PKCS#11 tokens implement protected authentication paths where possible (GnuTLS Security, Red Hat Bugzilla).
The vulnerability was part of a broader GnuTLS 3.8.13 release that addressed 12 security vulnerabilities, which received coverage from cybersecurity news outlets (CyberSecurityNews). Distribution vendors including Ubuntu (USN-8284-1), SUSE, Debian, openSUSE, and Amazon Linux 2023 issued their own security advisories. Community discussion was limited, consistent with the local-only, low-severity nature of the flaw.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."