Description
A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).
Problem types
Inefficient Algorithmic Complexity
Product status
Timeline
| 2025-12-17: | Reported to Red Hat. |
| 2026-02-09: | Made public. |
References
access.redhat.com/security/cve/CVE-2025-14831
bugzilla.redhat.com/show_bug.cgi?id=2423177 (RHBZ#2423177)