Buffer Overflow Vulnerability in GnuTLS Library Affects Multiple Applications
CVE-2025-9820

4MEDIUM

What is CVE-2025-9820?

A programming flaw within the GnuTLS library, particularly in the gnutls_pkcs11_token_init() function, leads to unsafe handling of PKCS#11 token labels. If a token label exceeds expected length, it results in a buffer overflow that can cause application crashes. This vulnerability may also be exploited to execute arbitrary code under certain conditions, endangering systems reliant on GnuTLS and potentially allowing attackers to escalate privileges or cause denial-of-service conditions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.