Denial of Service Vulnerability in GnuTLS
CVE-2025-14831

5.3MEDIUM

What is CVE-2025-14831?

A vulnerability in GnuTLS allows an attacker to exploit the system's processing capabilities, leading to denial of service (DoS) through specially crafted malicious certificates. These certificates may include a large number of name constraints and subject alternative names (SANs), resulting in excessive consumption of CPU and memory resources. This issue can severely impact performance and availability, making it crucial for affected users to implement the latest security patches.

Affected Version(s)

Red Hat AI Inference Server 3.2 sha256:54616c9f3e4d27120504b0b2020432ef3ff85286a50de7be842f05df0cfcd69e

Red Hat Ceph Storage 8 sha256:1160569002c25d3d349bbe41b57eeffade438853d3419edca01813227440f414

Red Hat Discovery 2 sha256:040dadd657afdb9f0914f896a4962fd3dbf40b70c8037e4d72b6801b766c9b7d

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.