CVE-2025-14831

Publication date 9 February 2026

Last updated 29 June 2026


Ubuntu priority

Cvss 3 Severity Score

5.3 · Medium

Score breakdown

Description

A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).

Read the notes from the security team

Status

Package Ubuntu Release Status
gnutls28 26.04 LTS resolute
Not affected
25.10 questing
Fixed 3.8.9-3ubuntu2.1
24.04 LTS noble
Fixed 3.8.3-1.1ubuntu3.5
22.04 LTS jammy
Fixed 3.7.3-4ubuntu1.8
20.04 LTS focal
Needs evaluation
18.04 LTS bionic
Needs evaluation
16.04 LTS xenial
Not affected

Notes


mrmajumder

esm-infra-legacy/xenial (gnutls28 3.4.10) is not-affected: its lib/x509/name_constraints.c has no name-constraint intersection logic at all (no _gnutls_name_constraints_intersect / name_constraints_node_list_intersect), only flat per-name checks (check_dns_constraints).

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
gnutls28

Severity score breakdown

CVSS version: CVSS v3.0

Base score 5.3 · Medium

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

References

Related Ubuntu Security Notices (USN)

    • USN-8043-1
    • GnuTLS vulnerabilities
    • 16 February 2026

Other references


Access our resources on patching vulnerabilities