Logo
vulnerabilityCVE-2025-32989
Name
CVE-2025-32989
Source
NVD ( link)Debian ( link)
Description
A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to create a certificate containing a malformed SCT extension (OID 1.3.6.1.4.1.11129.2.4.2) that contains sensitive data. This issue leads to the exposure of confidential information when GnuTLS verifies certificates from certain websites when the certificate (SCT) is not checked correctly.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
gnutls
Patched

Vulnerability Ratings#


5.3
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.8.13
Not Affected
buildroot
master
3.8.13
Not Affected
openwrt
master
3.8.10-r1
Not Affected
openwrt
openwrt-25.12
3.8.10-r1
Not Affected
yocto
master
3.8.13
Not Affected
yocto
scarthgap
3.8.4
Patched

Resolved with patches#


gnutls (yocto:kirkstone)

#
Title
Author
Resolve
1
x509: fix read buffer overrun in SCT timestamps
Andrew Hamilton <adhamilt@gmail.com>
CVE-2025-32989

gnutls (yocto:scarthgap)

#
Title
Author
Resolve
1
x509: fix read buffer overrun in SCT timestamps
Andrew Hamilton <adhamilt@gmail.com>
CVE-2025-32989