<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 06:48:51 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:16115 — Moderate: gnutls security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:16115</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: gnutls, AlmaLinux:10: gnutls-c++, AlmaLinux:10: gnutls-dane, AlmaLinux:10: gnutls-devel, AlmaLinux:10: gnutls-fips, AlmaLinux:10: gnutls-utils&lt;/p&gt;
&lt;p&gt;The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* gnutls: Vulnerability in GnuTLS certtool template parsing (CVE-2025-32990)
  * gnutls: Vulnerability in GnuTLS SCT extension parsing (CVE-2025-32989)
  * gnutls: Vulnerability in GnuTLS otherName SAN export (CVE-2025-32988)
  * gnutls: NULL pointer dereference in _gnutls_figure_common_ciphersuite() (CVE-2025-6395)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* gnutls: Vulnerability in GnuTLS certtool template parsing (BZ#2359620)
  * gnutls: Vulnerability in GnuTLS SCT extension parsing (BZ#2359621)
  * gnutls: Vulnerability in GnuTLS otherName SAN export (BZ#2359622)
  * gnutls: NULL pointer dereference in _gnutls_figure_common_ciphersuite() (BZ#2376755)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: gnutls, AlmaLinux:10: gnutls-c++, AlmaLinux:10: gnutls-dane, AlmaLinux:10: gnutls-devel, AlmaLinux:10: gnutls-fips, AlmaLinux:10: gnutls-utils&lt;/p&gt;
&lt;p&gt;The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* gnutls: Vulnerability in GnuTLS certtool template parsing (CVE-2025-32990)
  * gnutls: Vulnerability in GnuTLS SCT extension parsing (CVE-2025-32989)
  * gnutls: Vulnerability in GnuTLS otherName SAN export (CVE-2025-32988)
  * gnutls: NULL pointer dereference in _gnutls_figure_common_ciphersuite() (CVE-2025-6395)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* gnutls: Vulnerability in GnuTLS certtool template parsing (BZ#2359620)
  * gnutls: Vulnerability in GnuTLS SCT extension parsing (BZ#2359621)
  * gnutls: Vulnerability in GnuTLS otherName SAN export (BZ#2359622)
  * gnutls: NULL pointer dereference in _gnutls_figure_common_ciphersuite() (BZ#2376755)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:16115</guid>
    </item>
    <item>
      <title>bdu:2025-11074</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-11074</link>
      <description>bdu:2025-11074</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-11074</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-32990</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-32990</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: gnutls, Alpaquita:25: gnutls, Alpaquita:stream: gnutls&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: gnutls, Alpaquita:25: gnutls, Alpaquita:stream: gnutls&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-32990</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0622 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622</link>
      <description>certfr-2025-avi-0622</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622</guid>
    </item>
    <item>
      <title>EUVD-2026-362230</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-362230</link>
      <description>EUVD-2026-362230</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-362230</guid>
    </item>
    <item>
      <title>fkie_cve-2025-32990</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-32990</link>
      <description>&lt;p&gt;A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-32990</guid>
    </item>
    <item>
      <title>GHSA-v8v5-8mm8-3j8p</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v8v5-8mm8-3j8p</link>
      <description>&lt;p&gt;A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v8v5-8mm8-3j8p</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-32990 — Gnutls: vulnerability in gnutls certtool template parsing</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-32990</link>
      <description>msrc_CVE-2025-32990</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-32990</guid>
    </item>
    <item>
      <title>NCSC-2026-0022 — Kwetsbaarheden verholpen in Oracle Communications producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0022</link>
      <description>NCSC-2026-0022</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0022</guid>
    </item>
    <item>
      <title>OESA-2025-2007 — gnutls security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2007</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: gnutls&lt;/p&gt;
&lt;p&gt;GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, and other required structures. The project strives to provide a secure communications back-end, simple to use and integrated with the rest of the base Linux libraries. A back-end designed to work and be secure out of the box, keeping the complexity of TLS and PKI out of application code.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability, which was classified as critical, was found in GnuTLS (Network Encryption Software) (affected version unknown).CWE is classifying the issue as CWE-415. The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.This is going to have an impact on confidentiality, integrity, and availability.There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.(CVE-2025-32988)&lt;/p&gt;
&lt;p&gt;GnuTLS is a free secure communication library for implementing SSL, TLS and DTLS protocols.
 There is a security vulnerability in GnuTLS that originates from a heap buffer overflow in the certtool tool template parsing logic, which can lead to memory corruption and denial of service.(CVE-2025-32990)&lt;/p&gt;
&lt;p&gt;A vulnerability, which was classified as problematic, was found i…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: gnutls&lt;/p&gt;
&lt;p&gt;GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, and other required structures. The project strives to provide a secure communications back-end, simple to use and integrated with the rest of the base Linux libraries. A back-end designed to work and be secure out of the box, keeping the complexity of TLS and PKI out of application code.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability, which was classified as critical, was found in GnuTLS (Network Encryption Software) (affected version unknown).CWE is classifying the issue as CWE-415. The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.This is going to have an impact on confidentiality, integrity, and availability.There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.(CVE-2025-32988)&lt;/p&gt;
&lt;p&gt;GnuTLS is a free secure communication library for implementing SSL, TLS and DTLS protocols.
 There is a security vulnerability in GnuTLS that originates from a heap buffer overflow in the certtool tool template parsing logic, which can lead to memory corruption and denial of service.(CVE-2025-32990)&lt;/p&gt;
&lt;p&gt;A vulnerability, which was classified as problematic, was found i…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2007</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15411-1 — gnutls-3.8.10-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15411-1</link>
      <description>&lt;p&gt;gnutls-3.8.10-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;gnutls-3.8.10-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15411-1</guid>
    </item>
    <item>
      <title>RHSA-2025:16115 — Red Hat Security Advisory: gnutls security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:16115</link>
      <description>&lt;p&gt;gnutls: NULL pointer dereference in _gnutls_figure_common_ciphersuite() gnutls: Vulnerability in GnuTLS otherName SAN export gnutls: Vulnerability in GnuTLS SCT extension parsing gnutls: Vulnerability in GnuTLS certtool template parsing&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;gnutls: NULL pointer dereference in _gnutls_figure_common_ciphersuite() gnutls: Vulnerability in GnuTLS otherName SAN export gnutls: Vulnerability in GnuTLS SCT extension parsing gnutls: Vulnerability in GnuTLS certtool template parsing&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:16115</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:02340-1 — Security update for gnutls</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:02340-1</link>
      <description>&lt;p&gt;Security update for gnutls&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for gnutls&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:02340-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-32990</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-32990</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: gnutls28, Ubuntu:Pro:18.04:LTS: gnutls28, Ubuntu:Pro:20.04:LTS: gnutls28, Ubuntu:22.04:LTS: gnutls28, Ubuntu:Pro:FIPS-preview:22.04:LTS: gnutls28, Ubuntu:Pro:FIPS-updates:22.04:LTS: gnutls28, Ubuntu:24.04:LTS: gnutls28, Ubuntu:Pro:FIPS-updates:24.04:LTS: gnutls28, Ubuntu:25.10: gnutls28&lt;/p&gt;
&lt;p&gt;A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: gnutls28, Ubuntu:Pro:18.04:LTS: gnutls28, Ubuntu:Pro:20.04:LTS: gnutls28, Ubuntu:22.04:LTS: gnutls28, Ubuntu:Pro:FIPS-preview:22.04:LTS: gnutls28, Ubuntu:Pro:FIPS-updates:22.04:LTS: gnutls28, Ubuntu:24.04:LTS: gnutls28, Ubuntu:Pro:FIPS-updates:24.04:LTS: gnutls28, Ubuntu:25.10: gnutls28&lt;/p&gt;
&lt;p&gt;A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-32990</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1526 — GnuTLS: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1526</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in GnuTLS ausnutzen, um einen Denial of Service Angriff durchzuführen oder Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in GnuTLS ausnutzen, um einen Denial of Service Angriff durchzuführen oder Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1526</guid>
    </item>
  </channel>
</rss>
