CVE-2025-9820
EUVD-2025-20634426.01.2026, 20:16
A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a fixed-size stack buffer. This programming error can cause the application using GnuTLS to crash or, in certain conditions, be exploited for code execution. As a result, systems or applications relying on GnuTLS may be vulnerable to a denial of service or local privilege escalation attacks.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Siemens | SIMATIC CN 4100 | 𝑥 < V5.0 | ADP |
| siemens | simatic_cn_4100 | 𝑥 < 5.0 | ADP |
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| gnutls |
| ||||||||||||||||||
| libgnutls-devel |
| ||||||||||||||||||
| libgnutls-openssl-devel |
| ||||||||||||||||||
| libgnutls-openssl27 |
| ||||||||||||||||||
| libgnutls28 |
| ||||||||||||||||||
| libgnutls28-32bit |
| ||||||||||||||||||
| libgnutls30 |
| ||||||||||||||||||
| libgnutls30-32bit |
| ||||||||||||||||||
| libgnutls30-hmac |
| ||||||||||||||||||
| libgnutls30-hmac-32bit |
| ||||||||||||||||||
| libgnutlsxx-devel |
| ||||||||||||||||||
| libgnutlsxx28 |
| ||||||||||||||||||
| libgnutlsxx30 |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||
|---|---|---|---|---|---|
| gnutls |
| ||||
| gnutls-c |
| ||||
| gnutls-dane |
| ||||
| gnutls-devel |
| ||||
| gnutls-utils |
|
Azure Linux Releases
Common Weakness Enumeration
References