CVE-2025-32989
published 2025-07-10CVE-2025-32989: A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension…
PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
1.18%
64.1th percentile
A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to create a certificate containing a malformed SCT extension (OID 1.3.6.1.4.1.11129.2.4.2) that contains sensitive data. This issue leads to the exposure of confidential information when GnuTLS verifies certificates from certain websites when the certificate (SCT) is not checked correctly.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnutls28 | < gnutls28 3.7.9-2+deb12u5 (bookworm) | gnutls28 3.7.9-2+deb12u5 (bookworm) |
| msrc | azl3_gnutls_3.8.3-4_on_azure_linux_3.0 | — | — |
| msrc | azl3_gnutls_3.8.3-5_on_azure_linux_3.0 | — | — |
| msrc | cbl2_gnutls_3.7.11-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_gnutls_3.7.11-4_on_cbl_mariner_2.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv8.2HIGH
vendor_ubuntu6.5MEDIUM
vendor_debian5.3MEDIUM
vendor_msrc5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
gnutls28 vulnerabilities
osv·2025-07-14·CVSS 8.2
CVE-2025-32988 [HIGH] gnutls28 vulnerabilities
gnutls28 vulnerabilities
It was discovered that GnuTLS incorrectly handled exporting Subject
Alternative Name (SAN) entries containing an otherName. A remote attacker
could use this issue to cause GnuTLS to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2025-32988)
It was discovered that GnuTLS incorrectly handled parsing the Certificate
Transparency (CT) Signed Certificate Timestamp (SCT) extension. A remote
attacker could use this issue to cause GnuTLS to crash, resulting in a
denial of service, or possibly obtain sensitive information.
(CVE-2025-32989)
It was discovered that the GnuTLS certtool utility incorrectly handled
parsing certain template files. An attacker could use this issue to cause
GnuTLS to crash, resulting in a denial of service, or p
GHSA
GHSA-f7q5-qg45-7vm8: A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extens
ghsa_unreviewed·2025-07-10
CVE-2025-32989 [MEDIUM] CWE-295 GHSA-f7q5-qg45-7vm8: A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extens
A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to create a certificate containing a malformed SCT extension (OID 1.3.6.1.4.1.11129.2.4.2) that contains sensitive data. This issue leads to the exposure of confidential information when GnuTLS verifies certificates from certain websites when the certificate (SCT) is not checked correctly.
OSV
CVE-2025-32989: A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extens
osv·2025-07-10·CVSS 5.3
CVE-2025-32989 [MEDIUM] CVE-2025-32989: A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extens
A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to create a certificate containing a malformed SCT extension (OID 1.3.6.1.4.1.11129.2.4.2) that contains sensitive data. This issue leads to the exposure of confidential information when GnuTLS verifies certificates from certain websites when the certificate (SCT) is not checked correctly.
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2025-07-14·CVSS 6.5
CVE-2025-32990 [MEDIUM] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
It was discovered that GnuTLS incorrectly handled exporting Subject
Alternative Name (SAN) entries containing an otherName. A remote attacker
could use this issue to cause GnuTLS to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2025-32988)
It was discovered that GnuTLS incorrectly handled parsing the Certificate
Transparency (CT) Signed Certificate Timestamp (SCT) extension. A remote
attacker could use this issue to cause GnuTLS to crash, resulting in a
denial of service, or possibly obtain sensitive information.
(CVE-2025-32989)
It was discovered that the GnuTLS certtool utility incorrectly handled
parsing certain template files. An attacker could use this issue to
Red Hat
gnutls: Vulnerability in GnuTLS SCT extension parsing
vendor_redhat·2025-07-10·CVSS 5.3
CVE-2025-32989 [MEDIUM] CWE-295 gnutls: Vulnerability in GnuTLS SCT extension parsing
gnutls: Vulnerability in GnuTLS SCT extension parsing
A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to create a certificate containing a malformed SCT extension (OID 1.3.6.1.4.1.11129.2.4.2) that contains sensitive data. This issue leads to the exposure of confidential information when GnuTLS verifies certificates from certain websites when the certificate (SCT) is not checked correctly.
A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to create
Microsoft
Gnutls: vulnerability in gnutls sct extension parsing
vendor_msrc·2025-07-08·CVSS 5.3
CVE-2025-32989 [MEDIUM] CWE-295 Gnutls: vulnerability in gnutls sct extension parsing
Gnutls: vulnerability in gnutls sct extension parsing
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn
Debian
CVE-2025-32989: gnutls28 - A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the C...
vendor_debian·2025·CVSS 5.3
CVE-2025-32989 [MEDIUM] CVE-2025-32989: gnutls28 - A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the C...
A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to create a certificate containing a malformed SCT extension (OID 1.3.6.1.4.1.11129.2.4.2) that contains sensitive data. This issue leads to the exposure of confidential information when GnuTLS verifies certificates from certain websites when the certificate (SCT) is not checked correctly.
Scope: local
bookworm: resolved (fixed in 3.7.9-2+deb12u5)
bullseye: resolved
forky: resolved (fixed in 3.8.9-3)
sid: resolved (fixed in 3.8.9-3)
trixie: resolved (fixed in 3.8.9-3)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2025:16115https://access.redhat.com/errata/RHSA-2025:16116https://access.redhat.com/errata/RHSA-2025:17181https://access.redhat.com/errata/RHSA-2025:17348https://access.redhat.com/errata/RHSA-2025:17361https://access.redhat.com/errata/RHSA-2025:19088https://access.redhat.com/errata/RHSA-2025:22529https://access.redhat.com/errata/RHSA-2026:7477https://access.redhat.com/security/cve/CVE-2025-32989https://bugzilla.redhat.com/show_bug.cgi?id=2359621https://lists.gnupg.org/pipermail/gnutls-help/2025-July/004883.htmlhttp://www.openwall.com/lists/oss-security/2025/07/11/3https://cert-portal.siemens.com/productcert/html/ssa-082556.html
2025-07-10
Published