
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14831 is a Denial of Service (DoS) vulnerability in GnuTLS caused by excessive CPU and memory consumption during certificate verification. When GnuTLS attempts to verify a certificate chain containing a large number of name constraints and Subject Alternative Names (SANs), it processes all of them without any upper bound, making it susceptible to resource exhaustion attacks via specially crafted malicious certificates. The vulnerability was reported on 2025-12-17 and publicly disclosed on 2026-02-09. It affects GnuTLS broadly and has been confirmed in downstream distributions including RHEL 8, 9, and 10, Debian, Ubuntu, Fedora, SUSE, and Mageia, as well as IBM products (MQ Operator, Db2 on Cloud Pak for Data, CICS Transaction Gateway). It carries a CVSS v3.1 base score of 5.3 (Medium) (Red Hat CVE, Red Hat Bugzilla).
The root cause is classified as CWE-407 (Inefficient Algorithmic Complexity): GnuTLS's certificate verification logic iterates over all name constraints and SANs present in a certificate chain without imposing any limit on their quantity. An attacker can craft a certificate with an arbitrarily large number of these fields, causing the verification routine to consume disproportionate CPU and memory resources. The attack vector is network-based, requires no authentication or user interaction, and can be triggered in any context where GnuTLS is used to verify untrusted certificates — for example, during a TLS handshake where the server presents a malicious certificate to a GnuTLS-based client, or when using the certtool --verify command (Red Hat Bugzilla, Red Hat CVE).
Successful exploitation results in a denial of service through excessive CPU and memory consumption on the affected host, degrading or completely halting services that rely on GnuTLS for TLS/SSL operations. There is no confidentiality or integrity impact — the vulnerability is limited to availability. Systems running TLS servers or clients built on GnuTLS (including applications on RHEL, Debian, Ubuntu, SUSE, and IBM middleware products) are at risk of service disruption if they process attacker-controlled certificates (Red Hat CVE, Red Hat Bugzilla).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-14831. The EPSS score is approximately 0.03% (0.000300), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the ability to present a crafted certificate to a GnuTLS-based verifier, which is feasible in scenarios such as a malicious TLS server responding to a client, or a malicious certificate submitted for verification (Red Hat CVE).
certtool --verify)./var/log/kern.log or dmesg) triggered by GnuTLS-linked processes during certificate verification.The primary remediation is to update GnuTLS to a patched version. Red Hat has issued fixes across multiple RHEL versions: RHSA-2026:3477 (RHEL 10, gnutls-3.8.10-3.el10_1), RHSA-2026:4188 (RHEL 9, gnutls-3.8.3-10.el9_7), and RHSA-2026:5585 (RHEL 8). Additional errata cover RHEL EUS and SAP Solutions variants (RHSA-2026:6618, RHSA-2026:6630, RHSA-2026:6737, RHSA-2026:6738). Patches have also been released for Debian (DSA-6140-1, DLA-4492-1), Ubuntu (USN-8043-1), Fedora, SUSE, Mageia, and Slackware. IBM has addressed the issue in MQ Operator/container images, Db2 on Cloud Pak for Data, and CICS Transaction Gateway. No configuration-based workaround is documented; upgrading to a patched GnuTLS version is the recommended action (Red Hat RHSA-2026:3477, Red Hat RHSA-2026:4188, Red Hat Bugzilla).
The vulnerability received coverage from Linux security news outlets including SecurityOnline.info, LinuxSecurity.com, and Pro-Linux.de, which noted the fix in GnuTLS 3.8.12 alongside a TLS 1.3 crash fix. The oss-security mailing list carried the disclosure announcement. Community reaction has been measured, consistent with the moderate severity rating and lack of active exploitation. No notable threat actor attribution or significant social media controversy has been observed (oss-security, SecurityOnline).
Fix availability across major Linux distributions and their releases.
bookworm
gnutls28: 3.7.9-2+deb12u6
sid
gnutls28: 3.8.12-1
trixie
gnutls28: 3.8.9-3+deb13u2
bionic (esm-infra)
gnutls28: 3.5.18-1ubuntu1.6+esm3
devel
gnutls28
focal (esm-infra)
gnutls28: 3.6.13-2ubuntu1.12+esm2
jammy
gnutls28: 3.7.3-4ubuntu1.8
jammy (fips-preview)
gnutls28
jammy (fips-updates)
gnutls28: 3.7.3-4ubuntu1.8+Fips1.1
noble
gnutls28: 3.8.3-1.1ubuntu3.5
noble (fips-updates)
gnutls28: 3.8.3-1.1ubuntu3.5+Fips1.1
OpenShift
el8:rhpam-0:7-businesscentral-rhel8-container-7.13.5-4.1777325711
RHEL 8
:appstream:gnutls-0:3.6.16-8.el8_10.5.src
RHEL 9
:appstream:gnutls-0:3.7.6-21.el9_2.5.src
RHEL 10
gnutls-0:3.8.9-9.el10_0.17.src
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."