CVE Vulnerabilities

CVE-2025-6395

NULL Pointer Dereference

Published: Jul 10, 2025 | Modified: Dec 01, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
Ubuntu
MEDIUM

A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite().

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Red Hat Enterprise Linux 10 RedHat gnutls-0:3.8.9-9.el10_0.14 *
Red Hat Enterprise Linux 8 RedHat gnutls-0:3.6.16-8.el8_10.4 *
Red Hat Enterprise Linux 8 RedHat gnutls-0:3.6.16-8.el8_10.4 *
Red Hat Enterprise Linux 9 RedHat gnutls-0:3.8.3-6.el9_6.2 *
Red Hat Enterprise Linux 9 RedHat gnutls-0:3.8.3-6.el9_6.2 *
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions RedHat gnutls-0:3.7.6-21.el9_2.4 *
Red Hat Enterprise Linux 9.4 Extended Update Support RedHat gnutls-0:3.8.3-4.el9_4.4 *
Red Hat Ceph Storage 7 RedHat rhceph/rhceph-7-rhel9:sha256:4d2f9dc5b2b33ee1c77bbfabcbbb9f4d94d343b04c4de2e4f8b3b81a1f0fd2fe *
Red Hat Discovery 2 RedHat discovery/discovery-ui-rhel9:sha256:4784c2680572f9d091fcfb8c593d5424c0fcd8ea9cd51d25ddaf2f72abc7da65 *
Red Hat Insights proxy 1.5 RedHat insights-proxy/insights-proxy-container-rhel9:sha256:8eb6b896e1eac4080a564e146f95c4166e47ca137083b37119027c6a77011207 *
Gnutls28 Ubuntu devel *
Gnutls28 Ubuntu esm-infra/focal *
Gnutls28 Ubuntu fips-updates/jammy *
Gnutls28 Ubuntu fips-updates/noble *
Gnutls28 Ubuntu jammy *
Gnutls28 Ubuntu noble *
Gnutls28 Ubuntu oracular *
Gnutls28 Ubuntu plucky *
Gnutls28 Ubuntu questing *
Gnutls28 Ubuntu upstream *

Potential Mitigations

References