CVE-2025-6395NULL Pointer Dereference in Azl3 Gnutls 3.8.3-4 ON Azure Linux 3.0

Severity
6.5MEDIUMNVD
OSV8.2
EPSS
0.1%
top 77.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 10
Latest updateSep 9

Description

A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite().

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:HExploitability: 2.2 | Impact: 4.2

🔴Vulnerability Details

4
OSV
gnutls28 vulnerabilities2025-09-09
OSV
gnutls28 vulnerabilities2025-07-14
OSV
CVE-2025-6395: A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite()2025-07-10
GHSA
GHSA-prf7-7jvx-hxj5: A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite()2025-07-10

📋Vendor Advisories

5
Ubuntu
GnuTLS vulnerabilities2025-09-09
Ubuntu
GnuTLS vulnerabilities2025-07-14
Red Hat
gnutls: NULL pointer dereference in _gnutls_figure_common_ciphersuite()2025-07-10
Microsoft
Gnutls: null pointer dereference in _gnutls_figure_common_ciphersuite()2025-07-08
Debian
CVE-2025-6395: gnutls28 - A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figu...2025

🕵️Threat Intelligence

3
Wiz
CVE-2025-14831 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2025-9820 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-1584 Impact, Exploitability, and Mitigation Steps | Wiz