CVE-2026-42009: Dtls Duplicate Sequence Type Check

Simultaneously checking sequence number and message type (e.g. handshake type) to identify duplicate packets in a queue loop is unsafe. This pattern ignores duplicate sequence numbers that have mismatched types, leading to unstable packet sorting or Denial of Service (DoS) when invalid duplicated packets are improperly queued. Separate the conditions to chec

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0C
greprules fetch cve-2026-42009-dtls-duplicate-sequence-type-check --engine opengrep

Description

Simultaneously checking sequence number and message type (e.g. handshake type) to identify duplicate packets in a queue loop is unsafe. This pattern ignores duplicate sequence numbers that have mismatched types, leading to unstable packet sorting or Denial of Service (DoS) when invalid duplicated packets are improperly queued. Separate the conditions to chec