{
  "document": {
    "aggregate_severity": {
      "text": "High"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/centos6els/vex/2025/cve-2025-32988-els_os-centos6els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-15T08:59:07Z",
      "generator": {
        "date": "2026-09-15T08:59:07Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2025-32988-ELS_OS-CENTOS6ELS",
      "initial_release_date": "2025-07-10T08:15:00Z",
      "revision_history": [
        {
          "date": "2025-07-10T08:15:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-09-15T08:59:07Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2025-32988"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 6",
                "product": {
                  "name": "Community Enterprise Operating System 6",
                  "product_id": "CentOS-6",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:6:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.i686",
                "product": {
                  "name": "gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.i686",
                  "product_id": "gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/gnutls-devel@2.12.23-22.el6.tuxcare.els1?arch=i686"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.i686",
                "product": {
                  "name": "gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.i686",
                  "product_id": "gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/gnutls-guile@2.12.23-22.el6.tuxcare.els1?arch=i686"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "gnutls-0:2.12.23-22.el6.tuxcare.els1.i686",
                "product": {
                  "name": "gnutls-0:2.12.23-22.el6.tuxcare.els1.i686",
                  "product_id": "gnutls-0:2.12.23-22.el6.tuxcare.els1.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/gnutls@2.12.23-22.el6.tuxcare.els1?arch=i686"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "i686"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.x86_64",
                "product": {
                  "name": "gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.x86_64",
                  "product_id": "gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/gnutls-devel@2.12.23-22.el6.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.x86_64",
                "product": {
                  "name": "gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.x86_64",
                  "product_id": "gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/gnutls-guile@2.12.23-22.el6.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "gnutls-utils-0:2.12.23-22.el6.tuxcare.els1.x86_64",
                "product": {
                  "name": "gnutls-utils-0:2.12.23-22.el6.tuxcare.els1.x86_64",
                  "product_id": "gnutls-utils-0:2.12.23-22.el6.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/gnutls-utils@2.12.23-22.el6.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "gnutls-0:2.12.23-22.el6.tuxcare.els1.x86_64",
                "product": {
                  "name": "gnutls-0:2.12.23-22.el6.tuxcare.els1.x86_64",
                  "product_id": "gnutls-0:2.12.23-22.el6.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/gnutls@2.12.23-22.el6.tuxcare.els1?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "CloudLinux"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.i686 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.i686"
        },
        "product_reference": "gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.i686",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.x86_64"
        },
        "product_reference": "gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.x86_64"
        },
        "product_reference": "gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.i686 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.i686"
        },
        "product_reference": "gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.i686",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gnutls-utils-0:2.12.23-22.el6.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:gnutls-utils-0:2.12.23-22.el6.tuxcare.els1.x86_64"
        },
        "product_reference": "gnutls-utils-0:2.12.23-22.el6.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gnutls-0:2.12.23-22.el6.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:gnutls-0:2.12.23-22.el6.tuxcare.els1.x86_64"
        },
        "product_reference": "gnutls-0:2.12.23-22.el6.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gnutls-0:2.12.23-22.el6.tuxcare.els1.i686 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:gnutls-0:2.12.23-22.el6.tuxcare.els1.i686"
        },
        "product_reference": "gnutls-0:2.12.23-22.el6.tuxcare.els1.i686",
        "relates_to_product_reference": "CentOS-6"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-32988",
      "cwe": {
        "id": "CWE-415",
        "name": "Double Free"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS will call asn1_delete_structure() on an ASN.1 node it does not own, leading to a double-free condition when the parent function or caller later attempts to free the same structure.\n\nThis vulnerability can be triggered using only public GnuTLS APIs and may result in denial of service or memory corruption, depending on allocator behavior.",
          "title": "Vulnerability description"
        },
        {
          "category": "other",
          "text": "TuxCare has assessed that this vulnerability does not impact any currently supported TuxCare products. This evaluation may change as new information becomes available. For additional details regarding this vulnerability and affected products, refer to the provided references.",
          "title": "Statement"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "CentOS-6:gnutls-0:2.12.23-22.el6.tuxcare.els1.i686",
          "CentOS-6:gnutls-0:2.12.23-22.el6.tuxcare.els1.x86_64",
          "CentOS-6:gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.i686",
          "CentOS-6:gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.x86_64",
          "CentOS-6:gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.i686",
          "CentOS-6:gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.x86_64",
          "CentOS-6:gnutls-utils-0:2.12.23-22.el6.tuxcare.els1.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-32988"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:16115",
          "url": "https://access.redhat.com/errata/RHSA-2025:16115"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:16116",
          "url": "https://access.redhat.com/errata/RHSA-2025:16116"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:17181",
          "url": "https://access.redhat.com/errata/RHSA-2025:17181"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:17348",
          "url": "https://access.redhat.com/errata/RHSA-2025:17348"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:17361",
          "url": "https://access.redhat.com/errata/RHSA-2025:17361"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:17415",
          "url": "https://access.redhat.com/errata/RHSA-2025:17415"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:19088",
          "url": "https://access.redhat.com/errata/RHSA-2025:19088"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2025:22529",
          "url": "https://access.redhat.com/errata/RHSA-2025:22529"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:7477",
          "url": "https://access.redhat.com/errata/RHSA-2026:7477"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2025-32988",
          "url": "https://access.redhat.com/security/cve/CVE-2025-32988"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2359622",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359622"
        },
        {
          "category": "external",
          "summary": "https://lists.gnupg.org/pipermail/gnutls-help/2025-July/004883.html",
          "url": "https://lists.gnupg.org/pipermail/gnutls-help/2025-July/004883.html"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2025/07/11/3",
          "url": "http://www.openwall.com/lists/oss-security/2025/07/11/3"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/08/msg00005.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/08/msg00005.html"
        },
        {
          "category": "external",
          "summary": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html",
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        }
      ],
      "release_date": "2025-07-10T08:15:00Z",
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        },
        {
          "category": "impact",
          "date": "2026-09-02T12:13:33.723826Z",
          "details": "Not vulnerable. CVE-2025-32988 targets the _gnutls_write_new_othername path used when exporting SAN otherName entries, which was introduced together with the public otherName SAN APIs in GnuTLS 3.5.0 and later; the version in scope, GnuTLS 2.12.23, does not implement these APIs or the underlying function (the PoC fails to link gnutls_x509_crt_set_subject_alt_othername and gnutls_x509_crt_export2), so the vulnerable code path is absent and the issue is not exploitable.",
          "product_ids": [
            "CentOS-6:gnutls-0:2.12.23-22.el6.tuxcare.els1.i686",
            "CentOS-6:gnutls-0:2.12.23-22.el6.tuxcare.els1.x86_64",
            "CentOS-6:gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.i686",
            "CentOS-6:gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.x86_64",
            "CentOS-6:gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.i686",
            "CentOS-6:gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.x86_64",
            "CentOS-6:gnutls-utils-0:2.12.23-22.el6.tuxcare.els1.x86_64"
          ]
        }
      ]
    }
  ]
}