---
id: CVE-2026-42014
title: A flaw was found in GnuTLS
summary: >-
  A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used
  for changing the Security Officer PIN, can lead to a use-after-free
  vulnerability. This occurs when an attacker attempts to change the PIN with a
  NULL old PIN f…
severity: medium
cvss: 6.6
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H'
cwe:
  - CWE-825
published: '2026-06-16'
updated: '2026-06-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-42014'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:20611'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:20612'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:20613'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:26319'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:26409'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:29197'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:30004'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:30849'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:30850'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:32962'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-42014'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2467451'
    label: secalert@redhat.com
  - url: 'https://gitlab.com/gnutls/gnutls/-/issues/1766'
    label: secalert@redhat.com
  - url: 'https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-9'
    label: secalert@redhat.com
tags:
  - nvd
epss: 0.0015
epssPercentile: 0.04567
ingestedAt: '2026-06-29T13:42:11.968Z'
---

## Overview

A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
