DNA View

CVE-2025-32990

Medium
Low Medium High Critical
6.5
CVSS Score
Published: Jul 10, 2025
Last Modified: Apr 20, 2026

Vulnerability Description

A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Attack Vector
N
Attack Complexity
L
Privileges Required
N
User Interaction
N
Scope
U
Confidentiality
N
Integrity
L
Availability
L

Known Affected Software

7 configuration(s) from 2 vendor(s)

gnutls
Version:
-
CPE:
cpe:2.3:a:gnu:gnutls:-:*:*:*:*:*:*:*
enterprise_linux
Version:
7.0
CPE:
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:intel64:*
enterprise_linux
Version:
8.0
CPE:
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:arm64:*
enterprise_linux
Version:
10.0
CPE:
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
enterprise_linux
Version:
6.0
CPE:
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:intel64:*
openshift_container_platform
Version:
4.0
CPE:
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
enterprise_linux
Version:
9.0
CPE:
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
This vulnerability affects 7 software configuration(s). Ensure you patch all affected systems.

Available Security Patches

5 patches available from vendors

View All Patches
Oracle

CPUAPR2026

Oracle Critical Patch Update Advisory - April 2026

Severity
Critical
Released
Apr 21, 2026
Restart Required
Security Update
Oracle

CPUJAN2026

Oracle Critical Patch Update Advisory - January 2026

Severity
Critical
Released
Jan 20, 2026
Restart Required
Security Update
Oracle

CPUOCT2025

Oracle Critical Patch Update Advisory - October 2025

Severity
Critical
Released
Oct 21, 2025
Restart Required
Security Update
Microsoft

2025-Jul-CVE-2025-32990

CVE-2025-32990: Gnutls: vulnerability in gnutls certtool template parsing

Severity
Unknown
Released
Sep 17, 2025
Security Update
SUSE

CVE-2025-32990

CVE-2025-32990

Severity
Unknown
Released
Jul 12, 2025
Security Update

Severity Details

6.5
out of 10.0
Medium

Weakness Type (CWE)

CWE-122

Heap-based Buffer Overflow

Description
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Exploit Likelihood
High
Typical Severity
High
Abstraction Level
Variant

Key Information

Published Date
July 10, 2025