Denial of Service Vulnerability in GnuTLS
CVE-2025-14831

5.3MEDIUM

What is CVE-2025-14831?

A vulnerability in GnuTLS allows an attacker to exploit the system's processing capabilities, leading to denial of service (DoS) through specially crafted malicious certificates. These certificates may include a large number of name constraints and subject alternative names (SANs), resulting in excessive consumption of CPU and memory resources. This issue can severely impact performance and availability, making it crucial for affected users to implement the latest security patches.

Affected Version(s)

Red Hat AI Inference Server 3.2 1775740563

Red Hat AI Inference Server 3.3 1778244559

Red Hat AI Inference Server 3.3 1778244531

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.