---
id: CVE-2025-32989
title: >-
  A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the
  Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension
  during X.509 certificate parsing
summary: >-
  A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the
  Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension
  during X.509 certificate parsing. This flaw allows a malicious user to create
  a cer…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-295
vendor: gnu
product: gnutls
affected:
  - gnutls
  - openshift_container_platform = 4.0
  - enterprise_linux = 6.0
  - enterprise_linux = 7.0
  - enterprise_linux = 8.0
  - enterprise_linux = 9.0
  - enterprise_linux = 10.0
published: '2025-07-10'
updated: '2026-06-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-32989'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2025:16115'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:16116'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:17181'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:17348'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:17361'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:19088'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:22529'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:7477'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2025-32989'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2359621'
    label: secalert@redhat.com
  - url: 'https://lists.gnupg.org/pipermail/gnutls-help/2025-July/004883.html'
    label: secalert@redhat.com
  - url: 'http://www.openwall.com/lists/oss-security/2025/07/11/3'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-082556.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
tags:
  - nvd
epss: 0.01287
epssPercentile: 0.68916
ingestedAt: '2026-06-29T13:24:34.389Z'
---

## Overview

A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to create a certificate containing a malformed SCT extension (OID 1.3.6.1.4.1.11129.2.4.2) that contains sensitive data. This issue leads to the exposure of confidential information when GnuTLS verifies certificates from certain websites when the certificate (SCT) is not checked correctly.

## Affected

- `gnutls`
- `openshift_container_platform = 4.0`
- `enterprise_linux = 6.0`
- `enterprise_linux = 7.0`
- `enterprise_linux = 8.0`
- `enterprise_linux = 9.0`
- `enterprise_linux = 10.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
