PT-2025-29041 · Gnutls+9 · Gnutls+9

Published

2025-07-10

·

Updated

2026-03-29

·

CVE-2025-32989

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GnuTLS (affected versions not specified) gnutls28 versions prior to 3.7.9-2+deb12u5 gnutls30 versions prior to 3.8.10-alt1
Description GnuTLS is a library that implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS. A heap-buffer-overread issue exists in GnuTLS related to how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to create a certificate containing a malformed SCT extension (OID 1.3.6.1.4.1.11129.2.4.2) with sensitive data. The issue leads to the exposure of confidential information when GnuTLS verifies certificates from certain websites if the certificate (SCT) is not checked correctly. Exploitation of this issue may allow a remote attacker to gain unauthorized access to confidential information.
Recommendations Upgrade gnutls28 to version 3.7.9-2+deb12u5 or later. Upgrade gnutls30 to version 3.8.10-alt1 or later. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

ALSA-2025:16115
ALSA-2025:16116
ALT-PU-2025-9109
AZL-65088
AZL-65103
BDU:2025-11075
CVE-2025-32989
DSA-5962-1
INFSA-2025_16116
MGASA-2025-0225
OESA-2025-2009
OESA-2025-2010
OESA-2025-2011
OPENSUSE-SU-2025:15411-1
RHSA-2025:16115
RHSA-2025:16116
RHSA-2025_16116
RHSA-2026:7477
SUSE-SU-2025:02340-1
SUSE-SU-2025:02589-1
SUSE-SU-2025:02595-1
SUSE-SU-2025:20563-1
SUSE-SU-2025:20665-1
SUSE-SU-2025_02589-1
SUSE-SU-2025_02595-1
USN-7635-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Debian
Gnutls
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu