THREAT OPS › Threat News › [NVD] CVE-2025-32988 (MEDIUM 6.5) — A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS will call asn1_delete_structure()
[NVD] CVE-2025-32988 (MEDIUM 6.5) — A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS will call asn1_delete_structure()
CVE-2025-32988 CVSS: 6.5 MEDIUM Published: 2025-07-10T08:15:24.223
A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS will call asn1_delete_structure() on an ASN.1 node it does not own, leading to a doub
Indicators of compromise
- CVE-2025-32988cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-32988