Home

Description

A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.

PUBLISHED Reserved 2025-04-15 | Published 2025-07-10 | Updated 2026-04-20 | Assigner redhat




MEDIUM: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Problem types

Heap-based Buffer Overflow

Product status

Default status
unaffected

Any version before 3.8.10
affected

Default status
affected

0:3.8.9-9.el10_0.14 (rpm) before *
unaffected

Default status
affected

0:3.6.16-8.el8_10.4 (rpm) before *
unaffected

Default status
affected

0:3.6.16-8.el8_10.4 (rpm) before *
unaffected

Default status
affected

0:3.8.3-6.el9_6.2 (rpm) before *
unaffected

Default status
affected

0:3.8.3-6.el9_6.2 (rpm) before *
unaffected

Default status
affected

0:3.7.6-21.el9_2.4 (rpm) before *
unaffected

Default status
affected

0:3.8.3-4.el9_4.4 (rpm) before *
unaffected

Default status
affected

sha256:4d2f9dc5b2b33ee1c77bbfabcbbb9f4d94d343b04c4de2e4f8b3b81a1f0fd2fe (rpm) before *
unaffected

Default status
affected

sha256:435ba9959b793d46a63a74c343bb8c3ff68350496afec12cc5e894dfc40b7648 (rpm) before *
unaffected

Default status
affected

3.8.12-1.1.hum1 (rpm) before *
unaffected

Default status
affected

sha256:4ca38b33efec0d2dd17a8fd822a7c18281810676ceabb0c1db90953cb91cd5ea (rpm) before *
unaffected

Default status
unknown

Default status
unknown

Default status
affected

Timeline

2025-04-15:Reported to Red Hat.
2025-07-09:Made public.

References

lists.debian.org/debian-lts-announce/2025/08/msg00005.html

www.openwall.com/lists/oss-security/2025/07/11/3

access.redhat.com/errata/RHSA-2025:16115 (RHSA-2025:16115) vendor-advisory

access.redhat.com/errata/RHSA-2025:16116 (RHSA-2025:16116) vendor-advisory

access.redhat.com/errata/RHSA-2025:17181 (RHSA-2025:17181) vendor-advisory

access.redhat.com/errata/RHSA-2025:17348 (RHSA-2025:17348) vendor-advisory

access.redhat.com/errata/RHSA-2025:17361 (RHSA-2025:17361) vendor-advisory

access.redhat.com/errata/RHSA-2025:17415 (RHSA-2025:17415) vendor-advisory

access.redhat.com/errata/RHSA-2025:19088 (RHSA-2025:19088) vendor-advisory

access.redhat.com/errata/RHSA-2025:22529 (RHSA-2025:22529) vendor-advisory

access.redhat.com/errata/RHSA-2026:7477 (RHSA-2026:7477) vendor-advisory

access.redhat.com/security/cve/CVE-2025-32990 vdb-entry

bugzilla.redhat.com/show_bug.cgi?id=2359620 (RHBZ#2359620) issue-tracking

lists.gnupg.org/pipermail/gnutls-help/2025-July/004883.html

cve.org (CVE-2025-32990)

nvd.nist.gov (CVE-2025-32990)

Download JSON