CVE-2025-32990
published 2025-07-10CVE-2025-32990: A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain…
PriorityP343high8.2CVSS 3.1
AVNACLPRNUINSUCNILAH
EPSS
0.72%
49.8th percentile
A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| debian | gnutls28 | < gnutls28 3.7.9-2+deb12u5 (bookworm) | gnutls28 3.7.9-2+deb12u5 (bookworm) |
| msrc | azl3_gnutls_3.8.3-4_on_azure_linux_3.0 | — | — |
| msrc | azl3_gnutls_3.8.3-5_on_azure_linux_3.0 | — | — |
| msrc | cbl2_gnutls_3.7.11-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_gnutls_3.7.11-4_on_cbl_mariner_2.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
ghsa9.1CRITICAL
osv8.2HIGH
vendor_apache9.1
vendor_redhat9.1CRITICAL
vendor_oracle8.2MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Apache Tomcat: Apache Tomcat: Improper Input Validation vulnerability due to incomplete fix
vendor_redhat·2026-04-09·CVSS 9.1
CVE-2026-32990 [CRITICAL] CWE-184 Apache Tomcat: Apache Tomcat: Improper Input Validation vulnerability due to incomplete fix
Apache Tomcat: Apache Tomcat: Improper Input Validation vulnerability due to incomplete fix
A flaw was found in Apache Tomcat. This improper input validation vulnerability stems from an incomplete fix for a previous security issue (CVE-2025-66614). This flaw may allow an attacker to bypass security controls or cause unexpected behavior within the application.
Statement: Moderate impact. This improper input validation vulnerability in Apache Tomcat, stemming from an incomplete fix for CVE-2025-66614, affects Red Hat JBoss Web Server and Red Hat Enterprise Linux. An attacker could exploit this flaw to bypass security controls or induce unexpected application behavior.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat P
Oracle
Oracle Oracle Communications Risk Matrix: Platform (GnuTLS) — CVE-2025-32990
vendor_oracle·2026-01-15·CVSS 8.2
CVE-2025-32990 [MEDIUM] Oracle Oracle Communications Risk Matrix: Platform (GnuTLS) — CVE-2025-32990
Oracle Oracle Communications Risk Matrix: Platform (GnuTLS) vulnerability
CVE: CVE-2025-32990
CVSS: 8.2
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Security (GnuTLS) — CVE-2025-32990
vendor_oracle·2025-10-15·CVSS 8.2
CVE-2025-32990 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Security (GnuTLS) — CVE-2025-32990
Oracle Oracle Communications Applications Risk Matrix: Security (GnuTLS) vulnerability
CVE: CVE-2025-32990
CVSS: 8.2
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2025-09-09·CVSS 6.5
CVE-2025-32990 [MEDIUM] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
It was discovered that GnuTLS incorrectly handled exporting Subject
Alternative Name (SAN) entries containing an otherName. A remote attacker
could use this issue to cause GnuTLS to crash, resulting in a denial of
service, or possibly execute arbitrary code. This issue only affected
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2025-32988)
It was discovered that the GnuTLS certtool utility incorrectly handled
parsing certain template files. An attacker could use this issue to cause
GnuTLS to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2025-32990)
Stefan Bühler discovered that GnuTLS incorrectly handled parsing certain
template files. An attacker could possibly use th
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2025-07-14·CVSS 6.5
CVE-2025-32990 [MEDIUM] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
It was discovered that GnuTLS incorrectly handled exporting Subject
Alternative Name (SAN) entries containing an otherName. A remote attacker
could use this issue to cause GnuTLS to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2025-32988)
It was discovered that GnuTLS incorrectly handled parsing the Certificate
Transparency (CT) Signed Certificate Timestamp (SCT) extension. A remote
attacker could use this issue to cause GnuTLS to crash, resulting in a
denial of service, or possibly obtain sensitive information.
(CVE-2025-32989)
It was discovered that the GnuTLS certtool utility incorrectly handled
parsing certain template files. An attacker could use this issue to
Red Hat
gnutls: Vulnerability in GnuTLS certtool template parsing
vendor_redhat·2025-07-09·CVSS 6.5
CVE-2025-32990 [MEDIUM] CWE-122 gnutls: Vulnerability in GnuTLS certtool template parsing
gnutls: Vulnerability in GnuTLS certtool template parsing
A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.
A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.
Statement: This
Microsoft
Gnutls: vulnerability in gnutls certtool template parsing
vendor_msrc·2025-07-08·CVSS 6.5
CVE-2025-32990 [MEDIUM] CWE-122 Gnutls: vulnerability in gnutls certtool template parsing
Gnutls: vulnerability in gnutls certtool template parsing
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://l
Debian
CVE-2025-32990: gnutls28 - A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the...
vendor_debian·2025·CVSS 6.5
CVE-2025-32990 [MEDIUM] CVE-2025-32990: gnutls28 - A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the...
A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.
Scope: local
bookworm: resolved (fixed in 3.7.9-2+deb12u5)
bullseye: resolved (fixed in 3.7.1-5+deb11u8)
forky: resolved (fixed in 3.8.9-3)
sid: resolved (fixed in 3.8.9-3)
trixie: resolved (fixed in 3.8.9-3)
Apache
Apache tomcat: CVE-2025-66614
vendor_apache·CVSS 9.1
CVE-2025-66614 Apache tomcat: CVE-2025-66614
Apache tomcat: CVE-2025-66614
CVE-2026-32990 The validation of SNI name and host name did not take account of possible differences in case allowing the strict SNI checks to be bypassed. This was fixed with commit 021d1f83 . This issue was reported to the Tomcat security team on 13 March 2026. The issue was made public on 9 April 2026. Affects: 11.0.15 to 11.0.19 Note: The issues below were fixed in Apache Tomcat 11.0.19 but the release vote for the 11.0.19 release candidate did not pass. Therefore, although users must download 11.0.20 to obtain a version that includes a fix for these issues, version 11.0.19 is not included in the list of affected versions.
Severity: moderate
Affected versions: 11.0.19
GHSA
Apache Tomcat has an Improper Input Validation vulnerability
ghsa·2026-04-09·CVSS 9.1
CVE-2026-32990 [CRITICAL] CWE-20 Apache Tomcat has an Improper Input Validation vulnerability
Apache Tomcat has an Improper Input Validation vulnerability
Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614.
This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115.
Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
OSV
gnutls28 vulnerabilities
osv·2025-09-09·CVSS 8.2
CVE-2025-32988 [HIGH] gnutls28 vulnerabilities
gnutls28 vulnerabilities
It was discovered that GnuTLS incorrectly handled exporting Subject
Alternative Name (SAN) entries containing an otherName. A remote attacker
could use this issue to cause GnuTLS to crash, resulting in a denial of
service, or possibly execute arbitrary code. This issue only affected
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2025-32988)
It was discovered that the GnuTLS certtool utility incorrectly handled
parsing certain template files. An attacker could use this issue to cause
GnuTLS to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2025-32990)
Stefan Bühler discovered that GnuTLS incorrectly handled parsing certain
template files. An attacker could possibly use this issue to cause GnuTLS
to crash, resulting in a denial of s
OSV
gnutls28 vulnerabilities
osv·2025-07-14·CVSS 8.2
CVE-2025-32988 [HIGH] gnutls28 vulnerabilities
gnutls28 vulnerabilities
It was discovered that GnuTLS incorrectly handled exporting Subject
Alternative Name (SAN) entries containing an otherName. A remote attacker
could use this issue to cause GnuTLS to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2025-32988)
It was discovered that GnuTLS incorrectly handled parsing the Certificate
Transparency (CT) Signed Certificate Timestamp (SCT) extension. A remote
attacker could use this issue to cause GnuTLS to crash, resulting in a
denial of service, or possibly obtain sensitive information.
(CVE-2025-32989)
It was discovered that the GnuTLS certtool utility incorrectly handled
parsing certain template files. An attacker could use this issue to cause
GnuTLS to crash, resulting in a denial of service, or p
OSV
CVE-2025-32990: A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility
osv·2025-07-10·CVSS 8.2
CVE-2025-32990 [HIGH] CVE-2025-32990: A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility
A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.
GHSA
GHSA-v8v5-8mm8-3j8p: A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility
ghsa_unreviewed·2025-07-10
CVE-2025-32990 [MEDIUM] CWE-122 GHSA-v8v5-8mm8-3j8p: A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility
A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2025:16115https://access.redhat.com/errata/RHSA-2025:16116https://access.redhat.com/errata/RHSA-2025:17181https://access.redhat.com/errata/RHSA-2025:17348https://access.redhat.com/errata/RHSA-2025:17361https://access.redhat.com/errata/RHSA-2025:17415https://access.redhat.com/errata/RHSA-2025:19088https://access.redhat.com/errata/RHSA-2025:22529https://access.redhat.com/errata/RHSA-2026:7477https://access.redhat.com/security/cve/CVE-2025-32990https://bugzilla.redhat.com/show_bug.cgi?id=2359620https://lists.gnupg.org/pipermail/gnutls-help/2025-July/004883.htmlhttp://www.openwall.com/lists/oss-security/2025/07/11/3https://lists.debian.org/debian-lts-announce/2025/08/msg00005.html
2025-07-10
Published