- Description
- A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS will call asn1_delete_structure() on an ASN.1 node it does not own, leading to a double-free condition when the parent function or caller later attempts to free the same structure. This vulnerability can be triggered using only public GnuTLS APIs and may result in denial of service or memory corruption, depending on allocator behavior.
- Source
- secalert@redhat.com
- NVD status
- Modified
- Products
- gnutls, openshift_container_platform, enterprise_linux
CVSS 3.1
- Type
- Primary
- Base score
- 8.2
- Impact score
- 4.2
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
- Severity
- HIGH
- secalert@redhat.com
- CWE-415
- Hype score
- Not currently trending
⚠️ Vulnerabilidades en productos Juniper Networks ❗ CVE-2025-32990 ❗ CVE-2025-32988 ❗ CVE-2025-23048 ➡️ Más info: https://t.co/L2IfbfV9Gr https://t.co/PWDTxfgcCA
@CERTpy
18 Feb 2026
156 Impressions
1 Retweet
3 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Critical GnuTLS vulns (CVE-2025-32988, CVE-2025-32990) patched. Remote Code Execution risk for Ubuntu 18.04/20.04. Read more: 👉 https://t.co/E4Xk2is7S1 #Security #Ubuntu https://t.co/lpzvdTDVpT
@Cezar_H_Linux
12 Sept 2025
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔥CRITICAL #Debian 11 Patch! DLA-4267-1 fixes HIGH-SEV flaws in #GnuTLS (CVE-2025-6395, CVE-2025-32988 - RCE!, CVE-2025-32990). Exploits = DoS / Full System Compromise! Read more: 👉 https://t.co/0sRhKm4Yng https://t.co/kULDsi41QI
@Cezar_H_Linux
10 Aug 2025
39 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
URGENT: All #openSUSE Leap 15.4 users! gnutls update patches 4 CRITICAL flaws: CVE-2025-6395 (9.8 CVSS) CVE-2025-32988 (RCE risk) Patch command: zypper in -t patch SUSE-2025-2589=1 Full advisory ↓ Read more: 👉 https://t.co/jesXyALl9R https://t.co/5M85o3u62B
@Cezar_H_Linux
2 Aug 2025
31 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:*",
"matchCriteriaId": "0688D623-3000-48A8-957F-34B24905AA69",
"versionEndExcluding": "3.8.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*",
"matchCriteriaId": "932D137F-528B-4526-9A89-CD59FA1AB0FE",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*",
"matchCriteriaId": "2F6AB192-9D7D-4A9A-8995-E53A9DE9EAFC",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
"matchCriteriaId": "142AD0DD-4CF3-4D74-9442-459CE3347E3A",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*",
"matchCriteriaId": "F4CFF558-3C47-480D-A2F0-BABF26042943",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*",
"matchCriteriaId": "7F6FB57C-2BC7-487C-96DD-132683AEB35D",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*",
"matchCriteriaId": "D65C2163-CFC2-4ABB-8F4E-CB09CEBD006C",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]