<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T07:04:47.545269+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:16115</id>
    <title>ALSA-2025:16115 — Moderate: gnutls security, bug fix, and enhancement update</title>
    <updated>2026-10-04T07:04:47.641022+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: gnutls, AlmaLinux:10: gnutls-c++, AlmaLinux:10: gnutls-dane, AlmaLinux:10: gnutls-devel, AlmaLinux:10: gnutls-fips, AlmaLinux:10: gnutls-utils</p>
<p>The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS.</p>
<p>Security Fix(es):</p>
<p>* gnutls: Vulnerability in GnuTLS certtool template parsing (CVE-2025-32990)
  * gnutls: Vulnerability in GnuTLS SCT extension parsing (CVE-2025-32989)
  * gnutls: Vulnerability in GnuTLS otherName SAN export (CVE-2025-32988)
  * gnutls: NULL pointer dereference in _gnutls_figure_common_ciphersuite() (CVE-2025-6395)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* gnutls: Vulnerability in GnuTLS certtool template parsing (BZ#2359620)
  * gnutls: Vulnerability in GnuTLS SCT extension parsing (BZ#2359621)
  * gnutls: Vulnerability in GnuTLS otherName SAN export (BZ#2359622)
  * gnutls: NULL pointer dereference in _gnutls_figure_common_ciphersuite() (BZ#2376755)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:16115"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-11074</id>
    <title>bdu:2025-11074</title>
    <updated>2026-10-04T07:04:47.641103+00:00</updated>
    <content>bdu:2025-11074</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-11074"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-32990</id>
    <title>BELL-CVE-2025-32990</title>
    <updated>2026-10-04T07:04:47.641121+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: gnutls, Alpaquita:25: gnutls, Alpaquita:stream: gnutls</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-32990"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622</id>
    <title>certfr-2025-avi-0622 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
    <updated>2026-10-04T07:04:47.641144+00:00</updated>
    <content>certfr-2025-avi-0622</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-362230</id>
    <title>EUVD-2026-362230</title>
    <updated>2026-10-04T07:04:47.641160+00:00</updated>
    <content>EUVD-2026-362230</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-362230"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-32990</id>
    <title>fkie_cve-2025-32990</title>
    <updated>2026-10-04T07:04:47.641171+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-32990"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v8v5-8mm8-3j8p</id>
    <title>GHSA-v8v5-8mm8-3j8p</title>
    <updated>2026-10-04T07:04:47.641192+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v8v5-8mm8-3j8p"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-32990</id>
    <title>msrc_CVE-2025-32990 — Gnutls: vulnerability in gnutls certtool template parsing</title>
    <updated>2026-10-04T07:04:47.641222+00:00</updated>
    <content>msrc_CVE-2025-32990</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-32990"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0022</id>
    <title>NCSC-2026-0022 — Kwetsbaarheden verholpen in Oracle Communications producten</title>
    <updated>2026-10-04T07:04:47.641263+00:00</updated>
    <content>NCSC-2026-0022</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0022"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2007</id>
    <title>OESA-2025-2007 — gnutls security update</title>
    <updated>2026-10-04T07:04:47.641341+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: gnutls</p>
<p>GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, and other required structures. The project strives to provide a secure communications back-end, simple to use and integrated with the rest of the base Linux libraries. A back-end designed to work and be secure out of the box, keeping the complexity of TLS and PKI out of application code.

Security Fix(es):</p>
<p>A vulnerability, which was classified as critical, was found in GnuTLS (Network Encryption Software) (affected version unknown).CWE is classifying the issue as CWE-415. The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.This is going to have an impact on confidentiality, integrity, and availability.There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.(CVE-2025-32988)</p>
<p>GnuTLS is a free secure communication library for implementing SSL, TLS and DTLS protocols.
 There is a security vulnerability in GnuTLS that originates from a heap buffer overflow in the certtool tool template parsing logic, which can lead to memory corruption and denial of service.(CVE-2025-32990)</p>
<p>A vulnerability, which was classified as problematic, was found i…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2007"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15411-1</id>
    <title>openSUSE-SU-2025:15411-1 — gnutls-3.8.10-1.1 on GA media</title>
    <updated>2026-10-04T07:04:47.641380+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>gnutls-3.8.10-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15411-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:16115</id>
    <title>RHSA-2025:16115 — Red Hat Security Advisory: gnutls security, bug fix, and enhancement update</title>
    <updated>2026-10-04T07:04:47.641399+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>gnutls: NULL pointer dereference in _gnutls_figure_common_ciphersuite() gnutls: Vulnerability in GnuTLS otherName SAN export gnutls: Vulnerability in GnuTLS SCT extension parsing gnutls: Vulnerability in GnuTLS certtool template parsing</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:16115"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:02340-1</id>
    <title>SUSE-SU-2025:02340-1 — Security update for gnutls</title>
    <updated>2026-10-04T07:04:47.641421+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for gnutls</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:02340-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-32990</id>
    <title>UBUNTU-CVE-2025-32990</title>
    <updated>2026-10-04T07:04:47.641437+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: gnutls28, Ubuntu:Pro:18.04:LTS: gnutls28, Ubuntu:Pro:20.04:LTS: gnutls28, Ubuntu:22.04:LTS: gnutls28, Ubuntu:Pro:FIPS-preview:22.04:LTS: gnutls28, Ubuntu:Pro:FIPS-updates:22.04:LTS: gnutls28, Ubuntu:24.04:LTS: gnutls28, Ubuntu:Pro:FIPS-updates:24.04:LTS: gnutls28, Ubuntu:25.10: gnutls28</p>
<p>A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-32990"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1526</id>
    <title>WID-SEC-W-2025-1526 — GnuTLS: Mehrere Schwachstellen</title>
    <updated>2026-10-04T07:04:47.641469+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in GnuTLS ausnutzen, um einen Denial of Service Angriff durchzuführen oder Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1526"/>
  </entry>
</feed>
