Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-65100.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-65100
Upstream
Published
2025-07-10T10:15:33Z
Modified
2026-04-21T04:37:30.300532Z
Summary
CVE-2025-32990 affecting package gnutls for versions less than 3.8.3-6
Details

A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.

References

Affected packages

Azure Linux:3 / gnutls

Package

Name
gnutls
Purl
pkg:rpm/azure-linux/gnutls

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.8.3-6

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-65100.json"