Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4595-1 | gnutls28 security update |
Debian DSA |
DSA-6281-1 | gnutls28 security update |
Ubuntu USN |
USN-8284-1 | GnuTLS vulnerabilities |
Mon, 29 Jun 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:rhel_e4s:9.4::appstream cpe:/o:redhat:rhel_e4s:9.4::baseos |
|
| References |
|
Mon, 29 Jun 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat rhel Aus
Redhat rhel E4s Redhat rhel Eus Long Life Redhat rhel Tus |
|
| CPEs | cpe:/a:redhat:rhel_aus:8.6::appstream cpe:/a:redhat:rhel_e4s:8.8::appstream cpe:/a:redhat:rhel_eus_long_life:8.6::appstream cpe:/a:redhat:rhel_tus:8.8::appstream cpe:/o:redhat:rhel_aus:8.6::baseos cpe:/o:redhat:rhel_e4s:8.8::baseos cpe:/o:redhat:rhel_eus_long_life:8.6::baseos cpe:/o:redhat:rhel_tus:8.8::baseos |
|
| Vendors & Products |
Redhat rhel Aus
Redhat rhel E4s Redhat rhel Eus Long Life Redhat rhel Tus |
|
| References |
|
Fri, 26 Jun 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat rhel Eus
|
|
| CPEs | cpe:/a:redhat:rhel_eus:9.6::appstream cpe:/o:redhat:rhel_eus:9.6::baseos |
|
| Vendors & Products |
Redhat rhel Eus
|
|
| References |
|
Thu, 25 Jun 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Gnutls: fix use-after-free in gnutls_pkcs11_token_set_pin | Gnutls: gnutls: use-after-free in gnutls_pkcs11_token_set_pin |
Wed, 24 Jun 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat discovery
|
|
| CPEs | cpe:/a:redhat:discovery:2::el9 | |
| Vendors & Products |
Redhat discovery
|
|
| References |
|
Tue, 23 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gnu
Gnu gnutls Redhat hardened Images Redhat openshift Container Platform |
|
| Vendors & Products |
Gnu
Gnu gnutls Redhat hardened Images Redhat openshift Container Platform |
Tue, 16 Jun 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat enterprise Linux Eus
Redhat rhui |
|
| CPEs | cpe:/a:redhat:rhui:5::el9 cpe:/o:redhat:enterprise_linux_eus:10.0 |
|
| Vendors & Products |
Redhat enterprise Linux Eus
Redhat rhui |
|
| References |
|
Tue, 16 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 16 Jun 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path. | |
| Title | Gnutls: fix use-after-free in gnutls_pkcs11_token_set_pin | |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat hummingbird Redhat openshift |
|
| Weaknesses | CWE-825 | |
| CPEs | cpe:/a:redhat:enterprise_linux:8::appstream cpe:/a:redhat:enterprise_linux:9::appstream cpe:/a:redhat:hummingbird:1 cpe:/a:redhat:openshift:4 cpe:/o:redhat:enterprise_linux:10.2 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8::baseos cpe:/o:redhat:enterprise_linux:9::baseos |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat hummingbird Redhat openshift |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-06-29T10:18:31.826Z
Reserved: 2026-04-23T11:23:46.517Z
Link: CVE-2026-42014
Updated: 2026-06-16T15:22:25.722Z
Status : Awaiting Analysis
Published: 2026-06-16T02:16:19.140
Modified: 2026-06-16T15:26:04.250
Link: CVE-2026-42014
No data.
OpenCVE Enrichment
Updated: 2026-06-23T21:06:14Z
Debian DLA
Debian DSA
Ubuntu USN