Stack-based buffer overflow in GnuTLS - CVE-2025-9820

 

Stack-based buffer overflow in GnuTLS - CVE-2025-9820

Published: November 20, 2025


Vulnerability identifier: #VU118650
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-9820
CWE-ID: CWE-121
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error within the gnutls_pkcs11_token_init() function in lib/pkcs11_write.c when initializing the PKCS#11 token. A local user can trigger a stack-based buffer overflow and execute arbitrary code on the target system.


Affected software

GnuTLS
Debian Linux
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
gnutls-debugsource
libgnutls28
libgnutls28-32bit
libgnutls-openssl27-debuginfo
libgnutls-openssl-devel
libgnutls28-debuginfo-32bit
gnutls-debuginfo
libgnutls28-debuginfo
libgnutlsxx-devel
libgnutls-openssl27
libgnutls-devel
gnutls
gnutls28 (Ubuntu package)
libgnutls30-hmac
libgnutls30-debuginfo
libgnutls30
gnutls (Red Hat package)
gnutls-c++
gnutls-utils
gnutls-devel
gnutls-dane
gnutls-help
libgnutls30-32bit
gnutls-guile-debuginfo
gnutls-guile
libgnutlsxx28-debuginfo
libgnutlsxx28
libgnutls-devel-64bit
libgnutls30-hmac-64bit
libgnutls30-64bit-debuginfo
libgnutls30-64bit
libgnutls30-hmac-32bit
libgnutls-devel-32bit
libgnutls30-32bit-debuginfo
gnutls28 (Debian package)
gnutls-doc
libgnutlsxx30
libgnutlsxx30-debuginfo

How to mitigate CVE-2025-9820

Install updates from vendor's website.

GnuTLS - update to 3.8.11
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3.1 Patch 2
gnutls-debugsource - addressed in versions 3.3.27-3.15.1, 3.3.27-3.18.1, 3.6.7-150200.14.40.1, 3.7.3-150400.4.53.1, 3.7.3-150400.19.1, 3.8.3-150600.4.12.1
libgnutls28 - addressed in versions 3.3.27-3.15.1, 3.3.27-3.18.1
libgnutls28-32bit - addressed in versions 3.3.27-3.15.1, 3.3.27-3.18.1
libgnutls-openssl27-debuginfo - addressed in versions 3.3.27-3.15.1, 3.3.27-3.18.1
libgnutls-openssl-devel - addressed in versions 3.3.27-3.15.1, 3.3.27-3.18.1
libgnutls28-debuginfo-32bit - addressed in versions 3.3.27-3.15.1, 3.3.27-3.18.1
gnutls-debuginfo - addressed in versions 3.3.27-3.15.1, 3.3.27-3.18.1, 3.6.7-150200.14.40.1, 3.7.3-150400.4.53.1, 3.7.3-150400.19.1, 3.8.3-150600.4.12.1
libgnutls28-debuginfo - addressed in versions 3.3.27-3.15.1, 3.3.27-3.18.1
libgnutlsxx-devel - addressed in versions 3.3.27-3.15.1, 3.3.27-3.18.1, 3.7.3-150400.4.53.1, 3.8.3-150600.4.12.1
libgnutls-openssl27 - addressed in versions 3.3.27-3.15.1, 3.3.27-3.18.1
libgnutls-devel - addressed in versions 3.3.27-3.15.1, 3.3.27-3.18.1, 3.7.3-150400.4.53.1, 3.8.3-150600.4.12.1
gnutls - addressed in versions 3.3.27-3.15.1, 3.3.27-3.18.1, 3.6.7-150200.14.40.1, 3.7.3-150400.4.53.1, 3.7.3-150400.19.1, 3.8.3-150600.4.12.1
gnutls28 (Ubuntu package) - addressed in versions 3.4.10-4ubuntu1.9+esm3, 3.5.18-1ubuntu1.6+esm3, 3.6.13-2ubuntu1.12+esm2, 3.7.3-4ubuntu1.8, 3.8.3-1.1ubuntu3.5, 3.8.9-3ubuntu2.1
libgnutls30-hmac - addressed in versions 3.6.7-150200.14.40.1, 3.7.3-150400.4.53.1, 3.7.3-150400.19.1
libgnutls30-debuginfo - addressed in versions 3.6.7-150200.14.40.1, 3.7.3-150400.4.53.1, 3.7.3-150400.19.1, 3.8.3-150600.4.12.1
libgnutls30 - addressed in versions 3.6.7-150200.14.40.1, 3.7.3-150400.4.53.1, 3.7.3-150400.19.1, 3.8.3-150600.4.12.1
gnutls (Red Hat package) - addressed in versions 3.6.16-8.el8_10.5, 3.8.3-10.el9_7, 3.8.10-3.el10_1
gnutls-c++ - addressed in versions 3.6.16-8.0.2, 3.8.2-6
gnutls-utils - addressed in versions 3.6.16-8.0.2, 3.8.2-6
gnutls-devel - addressed in versions 3.6.16-8.0.2, 3.8.2-6
gnutls-dane - addressed in versions 3.6.16-8.0.2, 3.8.2-6
gnutls - addressed in versions 3.6.16-8.0.2, 3.8.2-6
gnutls-help - addressed in versions 3.7.2-17, 3.7.2-19, 3.8.2-9
gnutls-utils - addressed in versions 3.7.2-17, 3.7.2-19, 3.8.2-9
gnutls-devel - addressed in versions 3.7.2-17, 3.7.2-19, 3.8.2-9
gnutls-debugsource - addressed in versions 3.7.2-17, 3.7.2-19, 3.8.2-9
gnutls-debuginfo - addressed in versions 3.7.2-17, 3.7.2-19, 3.8.2-9
gnutls - addressed in versions 3.7.2-17, 3.7.2-19, 3.8.2-9
libgnutls30-32bit - addressed in versions 3.7.3-150400.4.53.1, 3.8.3-150600.4.12.1
gnutls-guile-debuginfo - update to 3.7.3-150400.4.53.1
gnutls-guile - update to 3.7.3-150400.4.53.1
libgnutlsxx28-debuginfo - update to 3.7.3-150400.4.53.1
libgnutlsxx28 - update to 3.7.3-150400.4.53.1
libgnutls-devel-64bit - addressed in versions 3.7.3-150400.4.53.1, 3.8.3-150600.4.12.1
libgnutls30-hmac-64bit - update to 3.7.3-150400.4.53.1
libgnutls30-64bit-debuginfo - addressed in versions 3.7.3-150400.4.53.1, 3.8.3-150600.4.12.1
libgnutls30-64bit - addressed in versions 3.7.3-150400.4.53.1, 3.8.3-150600.4.12.1
libgnutls30-hmac-32bit - update to 3.7.3-150400.4.53.1
libgnutls-devel-32bit - addressed in versions 3.7.3-150400.4.53.1, 3.8.3-150600.4.12.1
libgnutls30-32bit-debuginfo - addressed in versions 3.7.3-150400.4.53.1, 3.8.3-150600.4.12.1
gnutls28 (Debian package) - addressed in versions 3.7.9-2+deb12u6, 3.8.9-3+deb13u2
gnutls-doc - update to 3.8.2-6
gnutls-dane - update to 3.8.2-9
libgnutlsxx30 - update to 3.8.3-150600.4.12.1
libgnutlsxx30-debuginfo - update to 3.8.3-150600.4.12.1

External References

Related Security Bulletins