boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2025-32988

libgnutls — Gnutls: vulnerability in gnutls othername san export
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  H    8.2   .0137   71.0     —
AFFECTED
  Product                                                         Versions     Fixed
  libgnutls                                                       unspecified  —
  Red Hat Enterprise Linux 10                                     unspecified  0:3.8.9-9.el10_0.14
  Red Hat Enterprise Linux 8                                      unspecified  0:3.6.16-8.el8_10.4
  Red Hat Enterprise Linux 8                                      unspecified  0:3.6.16-8.el8_10.4
  Red Hat Enterprise Linux 9                                      unspecified  0:3.8.3-6.el9_6.2
  Red Hat Enterprise Linux 9                                      unspecified  0:3.8.3-6.el9_6.2
  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions  unspecified  0:3.7.6-21.el9_2.4
  Red Hat Enterprise Linux 9.4 Extended Update Support            unspecified  0:3.8.3-4.el9_4.4
  Red Hat Ceph Storage 7                                          unspecified  7
  Red Hat Discovery 2                                             unspecified  2.3.0-1760554384
  + 6 more
TIMELINE
  Apr 15  Reserved by redhat
  Jul 10  Published (CNA: redhat)
  Aug 21  RESCORED — CVE-2025-32988 (libgnutls). CVSS 6.5 → 8.2 (NVD).
CWE-415 · CNA: redhat · CVSS v3.1 · 15 references · NVD status: Modified

Description

A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS will call asn1_delete_structure() on an ASN.1 node it does not own, leading to a double-free condition when the parent function or caller later attempts to free the same structure. This vulnerability can be triggered using only public GnuTLS APIs and may result in denial of service or memory corruption, depending on allocator behavior.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
April 15, 2025ReservedReserved by redhat
July 10, 2025PublishedPublished (CNA: redhat)
August 21, 2026RESCOREDRESCORED — CVE-2025-32988 (libgnutls). CVSS 6.5 → 8.2 (NVD).

Affected

Affected products and packages — 16 rows
VendorProduct / PackageEcosystemVersion introducedFixed
—libgnutls———
Red HatRed Hat Enterprise Linux 10——0:3.8.9-9.el10_0.14
Red HatRed Hat Enterprise Linux 8——0:3.6.16-8.el8_10.4
Red HatRed Hat Enterprise Linux 8——0:3.6.16-8.el8_10.4
Red HatRed Hat Enterprise Linux 9——0:3.8.3-6.el9_6.2
Red HatRed Hat Enterprise Linux 9——0:3.8.3-6.el9_6.2
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions——0:3.7.6-21.el9_2.4
Red HatRed Hat Enterprise Linux 9.4 Extended Update Support——0:3.8.3-4.el9_4.4
Red HatRed Hat Ceph Storage 7——7
Red HatRed Hat Discovery 2——2.3.0-1760554384
Red HatRed Hat Hardened Images——3.8.12-1.1.hum1
Red HatRed Hat Insights proxy 1.5——1.5.7-1759331989
Red HatRed Hat Enterprise Linux 6———
Red HatRed Hat Enterprise Linux 7———
Red HatRed Hat OpenShift Container Platform 4———
Red HatRed Hat OpenShift Container Platform 4———

Weaknesses

CWE-415

References (15)

Related

Authoritative record: CVE-2025-32988 at cve.org

Vendors: red hat

Weaknesses: CWE-415

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-32988 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.