Buffer Overflow Vulnerability in GnuTLS Library Affects Multiple Applications
CVE-2025-9820

4MEDIUM

What is CVE-2025-9820?

A programming flaw within the GnuTLS library, particularly in the gnutls_pkcs11_token_init() function, leads to unsafe handling of PKCS#11 token labels. If a token label exceeds expected length, it results in a buffer overflow that can cause application crashes. This vulnerability may also be exploited to execute arbitrary code under certain conditions, endangering systems reliant on GnuTLS and potentially allowing attackers to escalate privileges or cause denial-of-service conditions.

Affected Version(s)

Red Hat Ceph Storage 8 sha256:1160569002c25d3d349bbe41b57eeffade438853d3419edca01813227440f414

Red Hat Discovery 2 sha256:040dadd657afdb9f0914f896a4962fd3dbf40b70c8037e4d72b6801b766c9b7d

Red Hat Discovery 2 sha256:062310de4b34e278f8c7e4634def673a77d1228d493541ef1264ba4cb83b68eb

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.