A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-06-16 02:16
Updated : 2026-09-01 13:19
NVD link : CVE-2026-42014
Mitre link : CVE-2026-42014
CVE.ORG link : CVE-2026-42014
JSON object : View
Products Affected
No product.
CWE
CWE-825
Expired Pointer Dereference
