{"id":"AZL-90149","summary":"CVE-2026-42014 affecting package gnutls for versions less than 3.8.13-1","details":"A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.","modified":"2026-08-28T17:48:11.190430438Z","published":"2026-06-16T02:16:19Z","upstream":["CVE-2026-42014"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42014"}],"affected":[{"package":{"name":"gnutls","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/gnutls"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.8.13-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-90149.json"}}],"schema_version":"1.9.0"}