CVE-2025-32990
Gnutls: vulnerability in gnutls certtool template parsing
A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Produtos afetados
libgnutlsRed Hat · Red Hat Ceph Storage 7Red Hat · Red Hat Discovery 2Red Hat · Red Hat Enterprise Linux 10Red Hat · Red Hat Enterprise Linux 6Red Hat · Red Hat Enterprise Linux 7Red Hat · Red Hat Enterprise Linux 8Red Hat · Red Hat Enterprise Linux 9Red Hat · Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRed Hat · Red Hat Enterprise Linux 9.4 Extended Update SupportRed Hat · Red Hat Hardened ImagesRed Hat · Red Hat Insights proxy 1.5Red Hat · Red Hat In-Vehicle Operating System 1Red Hat · Red Hat OpenShift Container Platform 4Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://access.redhat.com/errata/RHSA-2025:16115https://access.redhat.com/errata/RHSA-2025:16116https://access.redhat.com/errata/RHSA-2025:17181https://access.redhat.com/errata/RHSA-2025:17348https://access.redhat.com/errata/RHSA-2025:17361https://access.redhat.com/errata/RHSA-2025:17415https://access.redhat.com/errata/RHSA-2025:19088https://access.redhat.com/errata/RHSA-2025:22529https://access.redhat.com/errata/RHSA-2026:7477https://access.redhat.com/security/cve/CVE-2025-32990https://bugzilla.redhat.com/show_bug.cgi?id=2359620https://lists.debian.org/debian-lts-announce/2025/08/msg00005.html