CVE-2025-9820
A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a fixed-size stack buffer. This programming error can cause the application using GnuTLS to crash or, in certain conditions, be exploited for code execution. As a result, systems or applications relying on GnuTLS may be vulnerable to a denial of service or local privilege escalation attacks.
Published:Jan 26, 2026
Last Modified:Jun 30, 2026
EPS:Jan 26, 2026
EPSS Score:0.00203
CVSS Score:4
Affected Products
Vendor
Product
Action
Vendor
Redhat
Product
Ceph Storage
Redhat
Ceph Storage
Vendor
Redhat
Product
Discovery
Redhat
Discovery
Vendor
Redhat
Product
Enterprise Linux
Redhat
Enterprise Linux
Vendor
Redhat
Product
Hummingbird
Redhat
Hummingbird
Vendor
Redhat
Product
Insights Proxy
Redhat
Insights Proxy
Vendor
Redhat
Product
Openshift
Redhat
Openshift
Vendor
Redhat
Product
Rhosemc
Redhat
Rhosemc
Vendor
Redhat
Product
Rhui
Redhat
Rhui
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
