Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1271080 > unrolled thread

Bug#1121146: gnutls28: CVE-2025-9820

Started bySalvatore Bonaccorso <carnil@debian.org>
First post2025-11-21 20:20 +0100
Last post2025-11-22 06:50 +0100
Articles 2 — 2 participants

Back to article view | Back to linux.debian.bugs.dist


Contents

  Bug#1121146: gnutls28: CVE-2025-9820 Salvatore Bonaccorso <carnil@debian.org> - 2025-11-21 20:20 +0100
    Bug#1121146: gnutls28: CVE-2025-9820 Andreas Metzler <ametzler@bebt.de> - 2025-11-22 06:50 +0100

#1271080 — Bug#1121146: gnutls28: CVE-2025-9820

FromSalvatore Bonaccorso <carnil@debian.org>
Date2025-11-21 20:20 +0100
SubjectBug#1121146: gnutls28: CVE-2025-9820
Message-ID<LTEPL-eHlI-11@gated-at.bofh.it>
Source: gnutls28
Version: 3.8.10-3
Severity: important
Tags: security upstream
Forwarded: https://gitlab.com/gnutls/gnutls/-/issues/1732
X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org>

Hi,

The following vulnerability was published for gnutls28.

CVE-2025-9820[0]:
| GNUTLS-SA-2025-11-18: When a PKCS#11 token is initialized with
| gnutls_pkcs11_token_init function and it is passed a token label
| longer than 32 characters, it may write past the boundary of stack
| allocated memory. 

As we compile with -D_FORTIFY_SOURCE=2 it should be effectively
mitigated already but still might be worth bringing the fix in. But
no urgency IMHO, your take?

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-9820
    https://www.cve.org/CVERecord?id=CVE-2025-9820
[1] https://www.gnutls.org/security-new.html#GNUTLS-SA-2025-11-18
[2] https://gitlab.com/gnutls/gnutls/-/issues/1732

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

[toc] | [next] | [standalone]


#1271124

FromAndreas Metzler <ametzler@bebt.de>
Date2025-11-22 06:50 +0100
Message-ID<LTOFr-ePb2-5@gated-at.bofh.it>
In reply to#1271080
On 2025-11-21 Salvatore Bonaccorso <carnil@debian.org> wrote:
[...]
> As we compile with -D_FORTIFY_SOURCE=2 it should be effectively
> mitigated already but still might be worth bringing the fix in. But
> no urgency IMHO, your take?

I agree completely. Thanks for filing the tracker bug.

cu Andreas

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.dist


csiph-web