CVE-2025-32990

Updated: 2026-02-27 02:02:02.066257

Description:

A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 8.2

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

RHEL 7 ELS gnutls 3.3.29 8.2 HIGH Released CLSA-2025:1758022425 2025-09-16 22:40:17
TuxCare 9.6 ESU gnutls 3.8.3 8.2 HIGH Released CLSA-2025:1757949650 2025-09-16 00:49:12
Ubuntu 16.04 ELS gnutls28 3.4.10 8.2 HIGH Released CLSA-2025:1758915545 2025-09-26 23:48:10
Ubuntu 18.04 ELS gnutls28 3.5.18 8.2 HIGH Released CLSA-2025:1758915712 2025-09-26 23:48:09
Total: 14