Buffer Overflow Vulnerability in GnuTLS Library Affects Multiple Applications
CVE-2025-9820
4MEDIUM
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 26 January 2026
What is CVE-2025-9820?
A programming flaw within the GnuTLS library, particularly in the gnutls_pkcs11_token_init() function, leads to unsafe handling of PKCS#11 token labels. If a token label exceeds expected length, it results in a buffer overflow that can cause application crashes. This vulnerability may also be exploited to execute arbitrary code under certain conditions, endangering systems reliant on GnuTLS and potentially allowing attackers to escalate privileges or cause denial-of-service conditions.
Affected Version(s)
Red Hat Ceph Storage 8 1774002867
Red Hat Discovery 2 1775668717
Red Hat Discovery 2 1775675922