CVE-2026-42010

Publication date 7 May 2026

Last updated 29 June 2026


Ubuntu priority

Cvss 3 Severity Score

7.1 · High

Score breakdown

Description

A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.

Read the notes from the security team

Status

Package Ubuntu Release Status
gnutls28 26.04 LTS resolute
Fixed 3.8.12-2ubuntu1.1
25.10 questing
Fixed 3.8.9-3ubuntu2.2
24.04 LTS noble
Fixed 3.8.3-1.1ubuntu3.6
22.04 LTS jammy
Fixed 3.7.3-4ubuntu1.9
20.04 LTS focal
Needs evaluation
18.04 LTS bionic
Not affected
16.04 LTS xenial
Not affected

Notes


mrmajumder

xenial and bionic are not-affected: binary PSK identity support (the username_len field and the length parameter of _gnutls_psk_pwd_find_entry) was introduced in 3.6.13.

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
gnutls28

Severity score breakdown

CVSS version: CVSS v3.0

Base score 7.1 · High

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

References

Related Ubuntu Security Notices (USN)

Other references


Access our resources on patching vulnerabilities