CVE-2025-32988
published 2025-07-10CVE-2025-32988: A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name…
PriorityP345high8.2CVSS 3.1
AVNACLPRNUINSUCNILAH
EPSS
1.19%
64.3th percentile
A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS will call asn1_delete_structure() on an ASN.1 node it does not own, leading to a double-free condition when the parent function or caller later attempts to free the same structure.
This vulnerability can be triggered using only public GnuTLS APIs and may result in denial of service or memory corruption, depending on allocator behavior.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnutls28 | < gnutls28 3.7.9-2+deb12u5 (bookworm) | gnutls28 3.7.9-2+deb12u5 (bookworm) |
| gnu | gnutls | < 3.8.10 | 3.8.10 |
| gnu | gnutls | >= 0 < 3.8.12-r0 | 3.8.12-r0 |
| gnu | gnutls | >= 0 < 3.8.12-r0 | 3.8.12-r0 |
| gnu | gnutls | >= 0 < 3.8.12-r0 | 3.8.12-r0 |
| gnu | gnutls | >= 0 < 3.8.11-r0 | 3.8.11-r0 |
| msrc | azl3_gnutls_3.8.3-4_on_azure_linux_3.0 | — | — |
| msrc | azl3_gnutls_3.8.3-5_on_azure_linux_3.0 | — | — |
| msrc | cbl2_gnutls_3.7.11-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_gnutls_3.7.11-4_on_cbl_mariner_2.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
osv8.2HIGH
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_oracle6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
gnutls28 vulnerabilities
osv·2025-09-09·CVSS 8.2
CVE-2025-32988 [HIGH] gnutls28 vulnerabilities
gnutls28 vulnerabilities
It was discovered that GnuTLS incorrectly handled exporting Subject
Alternative Name (SAN) entries containing an otherName. A remote attacker
could use this issue to cause GnuTLS to crash, resulting in a denial of
service, or possibly execute arbitrary code. This issue only affected
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2025-32988)
It was discovered that the GnuTLS certtool utility incorrectly handled
parsing certain template files. An attacker could use this issue to cause
GnuTLS to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2025-32990)
Stefan Bühler discovered that GnuTLS incorrectly handled parsing certain
template files. An attacker could possibly use this issue to cause GnuTLS
to crash, resulting in a denial of s
OSV
gnutls28 vulnerabilities
osv·2025-07-14·CVSS 8.2
CVE-2025-32988 [HIGH] gnutls28 vulnerabilities
gnutls28 vulnerabilities
It was discovered that GnuTLS incorrectly handled exporting Subject
Alternative Name (SAN) entries containing an otherName. A remote attacker
could use this issue to cause GnuTLS to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2025-32988)
It was discovered that GnuTLS incorrectly handled parsing the Certificate
Transparency (CT) Signed Certificate Timestamp (SCT) extension. A remote
attacker could use this issue to cause GnuTLS to crash, resulting in a
denial of service, or possibly obtain sensitive information.
(CVE-2025-32989)
It was discovered that the GnuTLS certtool utility incorrectly handled
parsing certain template files. An attacker could use this issue to cause
GnuTLS to crash, resulting in a denial of service, or p
OSV
CVE-2025-32988: A flaw was found in GnuTLS
osv·2025-07-10·CVSS 8.2
CVE-2025-32988 [HIGH] CVE-2025-32988: A flaw was found in GnuTLS
A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS will call asn1_delete_structure() on an ASN.1 node it does not own, leading to a double-free condition when the parent function or caller later attempts to free the same structure. This vulnerability can be triggered using only public GnuTLS APIs and may result in denial of service or memory corruption, depending on allocator behavior.
GHSA
GHSA-fv5h-vqpf-6fqj: A flaw was found in GnuTLS
ghsa_unreviewed·2025-07-10
CVE-2025-32988 [MEDIUM] CWE-415 GHSA-fv5h-vqpf-6fqj: A flaw was found in GnuTLS
A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS will call asn1_delete_structure() on an ASN.1 node it does not own, leading to a double-free condition when the parent function or caller later attempts to free the same structure.
This vulnerability can be triggered using only public GnuTLS APIs and may result in denial of service or memory corruption, depending on allocator behavior.
OSV
CVE-2025-32988: A flaw was found in GnuTLS
osv·2025-07-10·CVSS 8.2
CVE-2025-32988 [HIGH] CVE-2025-32988: A flaw was found in GnuTLS
A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS will call asn1_delete_structure() on an ASN.1 node it does not own, leading to a double-free condition when the parent function or caller later attempts to free the same structure.
This vulnerability can be triggered using only public GnuTLS APIs and may result in denial of service or memory corruption, depending on allocator behavior.
Oracle
Oracle Oracle Communications Risk Matrix: Third Party (GnuTLS) — CVE-2025-32988
vendor_oracle·2026-01-15·CVSS 6.5
CVE-2025-32988 [MEDIUM] Oracle Oracle Communications Risk Matrix: Third Party (GnuTLS) — CVE-2025-32988
Oracle Oracle Communications Risk Matrix: Third Party (GnuTLS) vulnerability
CVE: CVE-2025-32988
CVSS: 6.5
Protocol: TLS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2025-09-09·CVSS 6.5
CVE-2025-32990 [MEDIUM] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
It was discovered that GnuTLS incorrectly handled exporting Subject
Alternative Name (SAN) entries containing an otherName. A remote attacker
could use this issue to cause GnuTLS to crash, resulting in a denial of
service, or possibly execute arbitrary code. This issue only affected
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2025-32988)
It was discovered that the GnuTLS certtool utility incorrectly handled
parsing certain template files. An attacker could use this issue to cause
GnuTLS to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2025-32990)
Stefan Bühler discovered that GnuTLS incorrectly handled parsing certain
template files. An attacker could possibly use th
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2025-07-14·CVSS 6.5
CVE-2025-32990 [MEDIUM] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
It was discovered that GnuTLS incorrectly handled exporting Subject
Alternative Name (SAN) entries containing an otherName. A remote attacker
could use this issue to cause GnuTLS to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2025-32988)
It was discovered that GnuTLS incorrectly handled parsing the Certificate
Transparency (CT) Signed Certificate Timestamp (SCT) extension. A remote
attacker could use this issue to cause GnuTLS to crash, resulting in a
denial of service, or possibly obtain sensitive information.
(CVE-2025-32989)
It was discovered that the GnuTLS certtool utility incorrectly handled
parsing certain template files. An attacker could use this issue to
Red Hat
gnutls: Vulnerability in GnuTLS otherName SAN export
vendor_redhat·2025-07-10·CVSS 6.5
CVE-2025-32988 [MEDIUM] CWE-415 gnutls: Vulnerability in GnuTLS otherName SAN export
gnutls: Vulnerability in GnuTLS otherName SAN export
A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS will call asn1_delete_structure() on an ASN.1 node it does not own, leading to a double-free condition when the parent function or caller later attempts to free the same structure.
This vulnerability can be triggered using only public GnuTLS APIs and may result in denial of service or memory corruption, depending on allocator behavior.
A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SA
Microsoft
Gnutls: vulnerability in gnutls othername san export
vendor_msrc·2025-07-08·CVSS 6.5
CVE-2025-32988 [MEDIUM] CWE-415 Gnutls: vulnerability in gnutls othername san export
Gnutls: vulnerability in gnutls othername san export
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.
Debian
CVE-2025-32988: gnutls28 - A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to ...
vendor_debian·2025·CVSS 6.5
CVE-2025-32988 [MEDIUM] CVE-2025-32988: gnutls28 - A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to ...
A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS will call asn1_delete_structure() on an ASN.1 node it does not own, leading to a double-free condition when the parent function or caller later attempts to free the same structure. This vulnerability can be triggered using only public GnuTLS APIs and may result in denial of service or memory corruption, depending on allocator behavior.
Scope: local
bookworm: resolved (fixed in 3.7.9-2+deb12u5)
bullseye: resolved (fixed in 3.7.1-5+deb11u8)
forky: resolved (fixed in 3.8.9-3)
sid: resolved (fixed in 3.8.9-3)
trixie: resolved (fixed in 3.8.9-3)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2025:16115https://access.redhat.com/errata/RHSA-2025:16116https://access.redhat.com/errata/RHSA-2025:17181https://access.redhat.com/errata/RHSA-2025:17348https://access.redhat.com/errata/RHSA-2025:17361https://access.redhat.com/errata/RHSA-2025:17415https://access.redhat.com/errata/RHSA-2025:19088https://access.redhat.com/errata/RHSA-2025:22529https://access.redhat.com/errata/RHSA-2026:7477https://access.redhat.com/security/cve/CVE-2025-32988https://bugzilla.redhat.com/show_bug.cgi?id=2359622https://lists.gnupg.org/pipermail/gnutls-help/2025-July/004883.htmlhttp://www.openwall.com/lists/oss-security/2025/07/11/3https://lists.debian.org/debian-lts-announce/2025/08/msg00005.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-082556.html
2025-07-10
Published