CVE-2025-32990

Updated: 2026-02-27 02:02:02.066257

Description:

A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 8.2

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU gnutls 3.7.6 8.2 HIGH Released CLSA-2025:1759247437 2025-09-30 16:21:52
Alpine Linux 3.18 ELS gnutls 3.8.4 8.2 HIGH Released CLSA-2025:1760989439 2025-10-20 21:30:46
CentOS 6 ELS gnutls 2.12.23 8.2 HIGH Not Vulnerable 2025-09-16 22:40:23 Not affected: the upstream fix for CVE-2025-32990 modifies the READ_MULTI_LINE macro used by certtoo...
CentOS 7 ELS gnutls 3.3.29 8.2 HIGH Released CLSA-2025:1758025991 2025-09-30 05:45:25
CentOS 8.4 ELS gnutls 3.6.14 8.2 HIGH Released CLSA-2025:1759334361 2025-10-02 01:25:58
CentOS 8.5 ELS gnutls 3.6.16 8.2 HIGH Released CLSA-2025:1759334959 2025-10-02 01:25:53
CentOS Stream 8 ELS gnutls 3.6.16 8.2 HIGH Released CLSA-2025:1759335207 2025-10-02 01:25:52
CloudLinux 7 ELS gnutls 3.3.29 8.2 HIGH Released CLSA-2025:1758023275 2025-09-30 05:45:32
Oracle Linux 6 ELS gnutls 2.12.23 8.2 HIGH Not Vulnerable 2025-09-16 22:40:20 Not affected: the upstream fix for CVE-2025-32990 modifies the READ_MULTI_LINE macro used by certtoo...
Oracle Linux 7 ELS gnutls 3.3.29 8.2 HIGH Released CLSA-2025:1758022501 2025-09-16 22:40:22
Total: 14