CVE-2025-6395
published 2025-07-10CVE-2025-6395: A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite().
PriorityP334medium6.5CVSS 3.1
AVNACHPRNUINSUCNILAH
EPSS
0.62%
45.7th percentile
A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite().
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnutls28 | < gnutls28 3.7.9-2+deb12u5 (bookworm) | gnutls28 3.7.9-2+deb12u5 (bookworm) |
| msrc | azl3_gnutls_3.8.3-4_on_azure_linux_3.0 | — | — |
| msrc | azl3_gnutls_3.8.3-6_on_azure_linux_3.0 | — | — |
| msrc | cbl2_gnutls_3.7.11-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_gnutls_3.7.11-4_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
osv8.2HIGH
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
gnutls28 vulnerabilities
osv·2025-09-09·CVSS 8.2
CVE-2025-32988 [HIGH] gnutls28 vulnerabilities
gnutls28 vulnerabilities
It was discovered that GnuTLS incorrectly handled exporting Subject
Alternative Name (SAN) entries containing an otherName. A remote attacker
could use this issue to cause GnuTLS to crash, resulting in a denial of
service, or possibly execute arbitrary code. This issue only affected
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2025-32988)
It was discovered that the GnuTLS certtool utility incorrectly handled
parsing certain template files. An attacker could use this issue to cause
GnuTLS to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2025-32990)
Stefan Bühler discovered that GnuTLS incorrectly handled parsing certain
template files. An attacker could possibly use this issue to cause GnuTLS
to crash, resulting in a denial of s
OSV
gnutls28 vulnerabilities
osv·2025-07-14·CVSS 8.2
CVE-2025-32988 [HIGH] gnutls28 vulnerabilities
gnutls28 vulnerabilities
It was discovered that GnuTLS incorrectly handled exporting Subject
Alternative Name (SAN) entries containing an otherName. A remote attacker
could use this issue to cause GnuTLS to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2025-32988)
It was discovered that GnuTLS incorrectly handled parsing the Certificate
Transparency (CT) Signed Certificate Timestamp (SCT) extension. A remote
attacker could use this issue to cause GnuTLS to crash, resulting in a
denial of service, or possibly obtain sensitive information.
(CVE-2025-32989)
It was discovered that the GnuTLS certtool utility incorrectly handled
parsing certain template files. An attacker could use this issue to cause
GnuTLS to crash, resulting in a denial of service, or p
OSV
CVE-2025-6395: A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite()
osv·2025-07-10·CVSS 6.5
CVE-2025-6395 [MEDIUM] CVE-2025-6395: A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite()
A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite().
GHSA
GHSA-prf7-7jvx-hxj5: A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite()
ghsa_unreviewed·2025-07-10
CVE-2025-6395 [MEDIUM] CWE-476 GHSA-prf7-7jvx-hxj5: A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite()
A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite(). When it reads certain settings from a template file, it can allow an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial of service (DoS) that could crash the system.
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2025-09-09·CVSS 6.5
CVE-2025-32990 [MEDIUM] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
It was discovered that GnuTLS incorrectly handled exporting Subject
Alternative Name (SAN) entries containing an otherName. A remote attacker
could use this issue to cause GnuTLS to crash, resulting in a denial of
service, or possibly execute arbitrary code. This issue only affected
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2025-32988)
It was discovered that the GnuTLS certtool utility incorrectly handled
parsing certain template files. An attacker could use this issue to cause
GnuTLS to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2025-32990)
Stefan Bühler discovered that GnuTLS incorrectly handled parsing certain
template files. An attacker could possibly use th
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2025-07-14·CVSS 6.5
CVE-2025-32990 [MEDIUM] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
It was discovered that GnuTLS incorrectly handled exporting Subject
Alternative Name (SAN) entries containing an otherName. A remote attacker
could use this issue to cause GnuTLS to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2025-32988)
It was discovered that GnuTLS incorrectly handled parsing the Certificate
Transparency (CT) Signed Certificate Timestamp (SCT) extension. A remote
attacker could use this issue to cause GnuTLS to crash, resulting in a
denial of service, or possibly obtain sensitive information.
(CVE-2025-32989)
It was discovered that the GnuTLS certtool utility incorrectly handled
parsing certain template files. An attacker could use this issue to
Red Hat
gnutls: NULL pointer dereference in _gnutls_figure_common_ciphersuite()
vendor_redhat·2025-07-10·CVSS 6.5
CVE-2025-6395 [MEDIUM] CWE-476 gnutls: NULL pointer dereference in _gnutls_figure_common_ciphersuite()
gnutls: NULL pointer dereference in _gnutls_figure_common_ciphersuite()
A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite().
A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite().
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: gnutls (Red Hat Enterprise Linux 6) - Out of support scope
Package: gnutls (Red Hat Enterprise Linux 7) - Out of support scope
Package: rhcos (Red Hat OpenShift Container Platform 4) - Fix deferred
Microsoft
Gnutls: null pointer dereference in _gnutls_figure_common_ciphersuite()
vendor_msrc·2025-07-08·CVSS 6.5
CVE-2025-6395 [MEDIUM] CWE-476 Gnutls: null pointer dereference in _gnutls_figure_common_ciphersuite()
Gnutls: null pointer dereference in _gnutls_figure_common_ciphersuite()
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Refere
Debian
CVE-2025-6395: gnutls28 - A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figu...
vendor_debian·2025·CVSS 6.5
CVE-2025-6395 [MEDIUM] CVE-2025-6395: gnutls28 - A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figu...
A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite().
Scope: local
bookworm: resolved (fixed in 3.7.9-2+deb12u5)
bullseye: resolved (fixed in 3.7.1-5+deb11u8)
forky: resolved (fixed in 3.8.9-3)
sid: resolved (fixed in 3.8.9-3)
trixie: resolved (fixed in 3.8.9-3)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-14831 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-14831 [HIGH] CVE-2025-14831 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14831 :
GnuTLS vulnerability analysis and mitigation
A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).
Source : NVD
## 5.3
Score
Published February 9, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
GnuTLS
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 19.8
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
libgnutls30-32bit
gnutls-guile
Sources
NVD
AlmaLinux 8 Severity MEDIUM Has Fix Added at: Mar 29, 2026
Wiz
CVE-2025-9820 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
CVE-2025-9820 [MEDIUM] CVE-2025-9820 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-9820 :
GnuTLS vulnerability analysis and mitigation
A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a fixed-size stack buffer. This programming error can cause the application using GnuTLS to crash or, in certain conditions, be exploited for code execution. As a result, systems or applications relying on GnuTLS may be vulnerable to a denial of service or local privilege escalation attacks.
Source : NVD
## 4
Score
Published January 26, 2026
Severity MEDIUM
CNA Score 4.0
Affected Technologies
GnuTLS
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA
Wiz
CVE-2026-1584 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-1584 [HIGH] CVE-2026-1584 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1584 :
GnuTLS vulnerability analysis and mitigation
A TLS 1.3 resumption attempt with an invalid PSK binder value in ClientHello could lead to a denial of service attack via crashing the server.
Source : NVD
Published February 10, 2026
CNA Score N/A
Affected Technologies
GnuTLS
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
gnutls-c++-debuginfo
gnutls-dane-debuginfo
Sources
NVD
Alpine 3.20, 3.21, 3.22, 3.23 Has Fix Added at: Feb 24, 2026
Alpine edge Has Fix Added at: Feb 11, 2026
Debian 14 Has Fix Added at: Feb 10, 2026
Debian Has Fix Added at: Feb 11, 2026
## Get a CVE risk assess
https://access.redhat.com/errata/RHSA-2025:16115https://access.redhat.com/errata/RHSA-2025:16116https://access.redhat.com/errata/RHSA-2025:17181https://access.redhat.com/errata/RHSA-2025:17348https://access.redhat.com/errata/RHSA-2025:17361https://access.redhat.com/errata/RHSA-2025:17415https://access.redhat.com/errata/RHSA-2025:19088https://access.redhat.com/errata/RHSA-2025:22529https://access.redhat.com/security/cve/CVE-2025-6395https://bugzilla.redhat.com/show_bug.cgi?id=2376755https://gitlab.com/gnutls/gnutls/-/issues/1718https://lists.gnupg.org/pipermail/gnutls-help/2025-July/004883.htmlhttp://www.openwall.com/lists/oss-security/2025/07/11/3https://lists.debian.org/debian-lts-announce/2025/08/msg00005.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-082556.html
2025-07-10
Published