USN-7281-1: GnuTLS vulnerability
USN-7281-1: GnuTLS vulnerability
20 February 2025
GnuTLS could be made to consume resources if it decoded specially crafted certificates.
Releases
Ubuntu 24.10 Ubuntu 24.04 LTS Ubuntu 22.04 LTS Ubuntu 20.04 LTS
Packages
gnutls28 - GNU TLS library
Details
Bing Shi discovered that GnuTLS incorrectly handled decoding certain
DER-encoded certificates. A remote attacker could possibly use this issue
to cause GnuTLS to consume resources, leading to a denial of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.10
- libgnutls30t64 - 3.8.6-2ubuntu1.1
Ubuntu 24.04 - libgnutls30t64 - 3.8.3-1.1ubuntu3.3
Ubuntu 22.04 - libgnutls30 - 3.7.3-4ubuntu1.6
Ubuntu 20.04
libgnutls30 - 3.6.13-2ubuntu1.12
In general, a standard system update will make all the necessary changes.