CVE-2026-42010

critical
Published 2026-05-07 · Modified 2026-05-27
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
VIR risk
9.8

Description

Important: gnutls security update

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2026-20611.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2467437

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2467289

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2467279

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450625

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450624

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2445763

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2026:20611

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2026-42010.html

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2026-42010

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://bugzilla.redhat.com/show_bug.cgi?id=2467289

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://access.redhat.com/security/cve/CVE-2026-42010

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed3.7.9-2+deb12u7
debian debianbullseyefixed3.7.1-5+deb11u10
debian debianforkyfixed3.8.13-1
debian debiansidfixed3.8.13-1
debian debiantrixiefixed3.8.9-3+deb13u4
suse slesaffected
redhat rhel6.0affected
redhat rhel7.0affected
redhat rhel8.0affected
redhat rhel9.0affected
redhat rhel10.0affected

Application impact

VendorProductVersionsFixed
gnugnutls-
redhathardened_images-
redhatopenshift_container_platform4.0

References

CWEs

CWE-626

Verify integrity in audit chain (admin only). AS-IS.