CVE Database
/

CVE-2025-9820

Back to search

CVE-2025-9820

Published: Jan 26, 2026

Modified: May 12, 2026

PUBLISHED

CVSS v3.1

4.0

MEDIUM

Description

A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a fixed-size stack buffer. This programming error can cause the application using GnuTLS to crash or, in certain conditions, be exploited for code execution. As a result, systems or applications relying on GnuTLS may be vulnerable to a denial of service or local privilege escalation attacks.

VendorProductVersions

Red Hat

Red Hat Enterprise Linux 10

unaffected
0:3.8.10-3.el10_1 - < *

Red Hat

Red Hat Enterprise Linux 8

unaffected
0:3.6.16-8.el8_10.5 - < *

Red Hat

Red Hat Enterprise Linux 8

unaffected
0:3.6.16-8.el8_10.5 - < *

Red Hat

Red Hat Enterprise Linux 9

unaffected
0:3.8.3-10.el9_7 - < *

Red Hat

Red Hat Enterprise Linux 9

unaffected
0:3.8.3-10.el9_7 - < *

Red Hat

RHEL-8 based Middleware Containers

unaffected
7.13.5-4.1777325677 - < *

Red Hat

RHEL-8 based Middleware Containers

unaffected
7.13.5-4.1777325711 - < *

Red Hat

RHEL-8 based Middleware Containers

unaffected
7.13.5-4.1777325710 - < *

Red Hat

RHEL-8 based Middleware Containers

unaffected
7.13.5-3.1777325680 - < *

Red Hat

RHEL-8 based Middleware Containers

unaffected
7.13.5-4.1777325709 - < *

Red Hat

RHEL-8 based Middleware Containers

unaffected
7.13.5-4.1777325680 - < *

Red Hat

RHEL-8 based Middleware Containers

unaffected
7.13.5-4.1777325708 - < *

Red Hat

Red Hat Ceph Storage 8

unaffected
1774002867 - < *

Red Hat

Red Hat Discovery 2

unaffected
1775668717 - < *

Red Hat

Red Hat Discovery 2

unaffected
1775675922 - < *

Red Hat

Red Hat Hardened Images

unaffected
3.8.12-1.1.hum1 - < *

Red Hat

Red Hat Insights proxy 1.5

unaffected
1773685509 - < *

Red Hat

Red Hat Update Infrastructure 5

unaffected
1773670073 - < *

Red Hat

Red Hat Update Infrastructure 5

unaffected
1773672059 - < *

Red Hat

Red Hat Update Infrastructure 5

unaffected
1773668803 - < *

Red Hat

Red Hat Update Infrastructure 5

unaffected
1773670137 - < *

Red Hat

Red Hat Enterprise Linux 6

All versions

Red Hat

Red Hat Enterprise Linux 7

All versions

Red Hat

Red Hat OpenShift Container Platform 4

All versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack Vector

Local

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

Low

References

RHSA-2026:13812
vendor-advisory
x_refsource_REDHAT
RHSA-2026:3477
vendor-advisory
x_refsource_REDHAT
RHSA-2026:4188
vendor-advisory
x_refsource_REDHAT
RHSA-2026:4655
vendor-advisory
x_refsource_REDHAT
RHSA-2026:4943
vendor-advisory
x_refsource_REDHAT
RHSA-2026:5585
vendor-advisory
x_refsource_REDHAT
RHSA-2026:5606
vendor-advisory
x_refsource_REDHAT
RHSA-2026:7329
vendor-advisory
x_refsource_REDHAT
RHSA-2026:7477
vendor-advisory
x_refsource_REDHAT
RHBZ#2392528
issue-tracking
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now