PageSourceSearch

https://docs-spectrocloud.netlify.app/assets/js/108f1ad6.4cb2510d.js

js docs-spectrocloud.netlify.app collected 2026-10-03 10:43:17 UTC 7,841 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkspectro_cloud_docs=self.webpackChunkspectro_cloud_docs||[]).push([["15075"],{615172:function(e,t,i){i.r(t),i.d(t,{frontMatter:()=>l,toc:()=>a,default:()=>h,metadata:()=>n,assets:()=>d,contentTitle:()=>c});var n=JSON.parse('{"id":"security-bulletins/reports/pc-cve-2025-32988","title":"CVE-2025-32988","description":"Lifecycle of CVE-2025-32988","source":"@site/docs/docs-content/security-bulletins/reports/pc-cve-2025-32988.md","sourceDirName":"security-bulletins/reports","slug":"/security-bulletins/reports/pc-cve-2025-32988","permalink":"/security-bulletins/reports/pc-cve-2025-32988","draft":false,"unlisted":false,"editUrl":"https://github.com/spectrocloud/librarium/blob/master/docs/docs-content/security-bulletins/reports/pc-cve-2025-32988.md","tags":[{"inline":true,"label":"security","permalink":"/tags/security"},{"inline":true,"label":"cve","permalink":"/tags/cve"}],"version":"current","lastUpdatedAt":null,"frontMatter":{"sidebar_label":"CVE-2025-32988","title":"CVE-2025-32988","description":"Lifecycle of CVE-2025-32988","sidebar_class_name":"hide-from-sidebar","hide_table_of_contents":false,"toc_max_heading_level":2,"tags":["security","cve"]},"sidebar":"docSidebar","previous":{"title":"CVE-2025-3277","permalink":"/security-bulletins/reports/pc-cve-2025-3277"},"next":{"title":"CVE-2025-43967","permalink":"/security-bulletins/reports/pc-cve-2025-43967"}}'),r=i(474848),s=i(884429);let l={sidebar_label:"CVE-2025-32988",title:"CVE-2025-32988",description:"Lifecycle of CVE-2025-32988",sidebar_class_name:"hide-from-sidebar",hide_table_of_contents:!1,toc_max_heading_level:2,tags:["security","cve"]},c,d={},a=[{value:"CVE Details",id:"cve-details",level:2},{value:"Initial Publication",id:"initial-publication",level:2},{value:"Last Update",id:"last-update",level:2},{value:"Third Party Dependency",id:"third-party-dependency",level:2},{value:"NIST CVE Summary",id:"nist-cve-summary",level:2},{value:"CVE Severity",id:"cve-severity",level:2},{value:"Our Official Summary",id:"our-official-summary",level:2},{value:"Status",id:"status",level:2},{value:"Affected Products & Versions",id:"affected-products--versions",level:2},{value:"Revision History",id:"revision-history",level:2}];function o(e){let t={a:"a",h2:"h2",p:"p",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",...(0,s.R)(),...e.components};return(0,r.jsxs)(r.Fragment,{children:[(0,r.jsx)(t.h2,{id:"cve-details",children:"CVE Details"}),"\n",(0,r.jsxs)(t.p,{children:["Visit the official vulnerability details page for ",(0,r.jsx)(t.a,{href:"https://nvd.nist.gov/vuln/detail/cve-2025-32988",children:"CVE-2025-32988"})," to learn more."]}),"\n",(0,r.jsx)(t.h2,{id:"initial-publication",children:"Initial Publication"}),"\n",(0,r.jsx)(t.p,{children:"07/11/2025"}),"\n",(0,r.jsx)(t.h2,{id:"last-update",children:"Last Update"}),"\n",(0,r.jsx)(t.p,{children:"04/23/2026"}),"\n",(0,r.jsx)(t.h2,{id:"third-party-dependency",children:"Third Party Dependency"}),"\n",(0,r.jsx)(t.p,{children:"libgnutls30"}),"\n",(0,r.jsx)(t.h2,{id:"nist-cve-summary",children:"NIST CVE Summary"}),"\n",(0,r.jsx)(t.p,{children:"A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invali
1d or malformed, GnuTLS will call asn1_delete_structure() on an ASN.1 node it does not own, leading to a double-free condition when the parent function or caller later attempts to free the same structure."}),"\n",(0,r.jsx)(t.p,{children:"This vulnerability can be triggered using only public GnuTLS APIs and may result in denial of service or memory corruption, depending on allocator behavior."}),"\n",(0,r.jsx)(t.h2,{id:"cve-severity",children:"CVE Severity"}),"\n",(0,r.jsx)(t.p,{children:(0,r.jsx)(t.a,{href:"https://nvd.nist.gov/vuln/detail/cve-2025-32988",children:"8.2"})}),"\n",(0,r.jsx)(t.h2,{id:"our-official-summary",children:"Our Official Summary"}),"\n",(0,r.jsx)(t.p,{children:"This is a double-free memory vulnerability in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. When processing certificates with invalid or malformed type-id OIDs, GnuTLS incorrectly calls asn1_delete_structure() on an ASN.1 node it does not own, leading to a double-free condition when the parent function attempts to free the same structure. This vulnerability can be triggered using only public GnuTLS APIs."}),"\n",(0,r.jsx)(t.p,{children:"The vulnerability affects kubevirt and harbor components. If these components are not used, this vulnerability does not apply. However, successful exploitation requires processing specifically crafted X.509 certificates with malformed SAN entries, which is typically controlled through certificate validation processes and trusted certificate authorities in our environments."}),"\n",(0,r.jsx)(t.p,{children:"The risk of exploitation is considered medium, as it requires an attacker to present malformed certificates that would trigger the vulnerable code path during TLS/SSL certificate processing."}),"\n",(0,r.jsx)(t.p,{children:"Upstream patches addressing this issue will be adopted as and when they become available."}),"\n",(0,r.jsx)(t.h2,{id:"status",children:"Status"}),"\n",(0,r.jsx)(t.p,{children:"Ongoing"}),"\n",(0,r.jsx)(t.h2,{id:"affected-products--versions",children:"Affected Products & Versions"}),"\n",(0,r.jsxs)(t.table,{children:[(0,r.jsx)(t.thead,{children:(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.th,{children:"Version"}),(0,r.jsx)(t.th,{children:"Palette Enterprise"}),(0,r.jsx)(t.th,{children:"Palette Enterprise Airgap"}),(0,r.jsx)(t.th,{children:"VerteX"}),(0,r.jsx)(t.th,{children:"VerteX Airgap"})]})}),(0,r.jsxs)(t.tbody,{children:[(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"4.8.52"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u2705 No Impact"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u2705 No Impact"})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"4.7.29"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"4.6.41"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u2705 No Impact"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"})]})]})]}),"\n",(0,r.jsx)(t.h2,{id:"revision-history",children:"Revision History"}),"\n",(0,r.jsxs)(t.table,{children:[(0,r.jsx)(t.thead,{children:(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.th,{children:"Date"}),(0,r.jsx)(t.th,{children:"Revision"})]})}),(0,r.jsxs)(t.tbody,{children:[(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"09/17/2025"}),(0,r.jsx)(t.td,{children:"Status changed from Open to Ongoing"})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"09/17/2025"}),(0,r.jsx)(t.td,{children:"Official summary added"})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"08/22/2025"}),(0,r.jsx)(t.td,{children:"Advisory severity revised to HIGH from MEDIUM"})]})]})]})]})}function h(e={}){let{wrapper:t}={...(0,s.R)(),...e.components};return t?(0,r.jsx)(t,{...e,children:(0,r.jsx)(o,{...e})}):o(e)}},884429:function(e,t,i){i.d(t,{R:()=>l,x:()=>c});var n=i(296540);let r={},s=n.createContext(r);function l(e){let t=n.useContext(s);return n.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function c(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(r):e.components||r:l(e.components),n.createElement(s.Provider,{value:t},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.