CVE-2025-32989 Details
Description
A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to create a certificate containing a malformed SCT extension (OID 1.3.6.1.4.1.11129.2.4.2) that contains sensitive data. This issue leads to the exposure of confidential information when GnuTLS verifies certificates from certain websites when the certificate (SCT) is not checked correctly.
A heap-buffer-overread vulnerability exists in GnuTLS related to the handling of the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This vulnerability allows a malicious user to craft a certificate with a malformed SCT extension that includes sensitive data. As a result, confidential information may be exposed when GnuTLS verifies certificates from certain websites, particularly when the certificate's SCT is not properly validated.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gnu gnutls | All versions |
CPE
Remediation
| |
| redhat openshift container platform | 4.0 |
CPE
Remediation
| |
| redhat enterprise linux | 6.0 7.0 8.0 9.0 10.0 |
CPE
Remediation
| |
Change History
23 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 1, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | CVE |
| Aug 31, 2026 | CVE Modified | siemens-SADP |
| Aug 21, 2026 | CVE Modified | [email protected] |
| Jun 30, 2026 | CVE Modified | [email protected] |
| Jun 25, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | siemens-SADP |
| May 12, 2026 | CVE Modified | siemens-SADP |
| Apr 20, 2026 | CVE Modified | [email protected] |
| Apr 14, 2026 | CVE Modified | [email protected] |
| Dec 1, 2025 | CVE Modified | [email protected] |
| Nov 6, 2025 | CVE Modified | [email protected] |
| Nov 4, 2025 | CVE Modified | CVE |
| Oct 23, 2025 | CVE Modified | [email protected] |
| Oct 6, 2025 | CVE Modified | [email protected] |
| Oct 6, 2025 | CVE Modified | [email protected] |
| Sep 17, 2025 | CVE Modified | [email protected] |
| Sep 17, 2025 | CVE Modified | [email protected] |
| Aug 15, 2025 | Initial Analysis | [email protected] |
| Jul 10, 2025 | New CVE Received | [email protected] |