Ubuntu alert USN-8043-1 (gnutls28)
| From: | noreply+usn-bot@canonical.com | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8043-1] GnuTLS vulnerabilities | |
| Date: | Mon, 16 Feb 2026 16:28:48 +0000 | |
| Message-ID: | <E1vs1Sq-00032E-Te@lists.ubuntu.com> |
========================================================================== Ubuntu Security Notice USN-8043-1 February 16, 2026 gnutls28 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in GnuTLS. Software Description: - gnutls28: GNU TLS library Details: Tim Scheckenbach discovered that GnuTLS incorrectly handled malicious certificates containing a large number of name constraints and subject alternative names. A remote attacker could possibly use this issue to cause GnuTLS to consume resources, resulting in a denial of service. (CVE-2025-14831) Luigino Camastra discovered that GnuTLS incorrectly handled certain PKCS11 token labels. A remote attacker could use this issue to cause GnuTLS to crash, resulting in a denial of service, or possibly execute arbitrary code. The default compiler options for affected releases should reduce the vulnerability to a denial of service. (CVE-2025-9820) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 libgnutls30t64 3.8.9-3ubuntu2.1 Ubuntu 24.04 LTS libgnutls30t64 3.8.3-1.1ubuntu3.5 Ubuntu 22.04 LTS libgnutls30 3.7.3-4ubuntu1.8 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8043-1 CVE-2025-14831, CVE-2025-9820 Package Information: https://launchpad.net/ubuntu/+source/gnutls28/3.8.9-3ubun... https://launchpad.net/ubuntu/+source/gnutls28/3.8.3-1.1ub... https://launchpad.net/ubuntu/+source/gnutls28/3.7.3-4ubun...
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmmTRUcACgkQcpJm3tlz hgE/rw/+NEy2+CZt31OFEWvm2zWOsiI86xy/Sr979H95UCt3UtKKpl3zQlDKYEMG lG+QsJEuSOS0Ty6rqYSirhHTD7ubGNTDMBnIvnvF5vlArexVwyiFTgFccY+XtiwM LyCCxIO8sqVZ3UOSe8V40VjczIqCN3BaBySTD9AiQA+0nhgcjHqlE79KMCtEP5QP 8FY5J6PFsbCEHHL6UlZZrwJWorBMklGCGUUrjZ4SKOOcoymIZgKcWeDSrZD/xMpt z3s0pd2WCZHS45MRVTxI3AwuGDf5g01qb/OQ02sq5r3e13F0CN7Rh/kWTeK548z+ ONAUSCpRQPV/Gxc++7iYs03ZWWkhUNgVIe29tdCC+BtM8q45Mgj067BkU+rmSXv4 x2HJaHZDPzue23uWnMGWgHnzy9hBqy/gVcsg21SQae3peNVNSulZTXnxEdo17SWi 03hPCEw5Vfg3jAAhJMV1H3xaiv1RoSyHMGrLwsLO0hdKjMi+5c5ipCCM1XD/26Bz Umr35syJyyeL/tvbyf5qsWIb+UqhJzXCpVeQBcXzbQmfF2QgJQjRYMwbwBgng1FJ 0iZeaPvK1CKOZmLTiwYom+cvqAbBOn1Pcv1TTNpVZGM1inQ6l8kBIuY1xNUKeLH6 WloDpS/fVsDQqoE66iFwKKymtcQguFNyySBE3N2yaeuOBvgmgZE= =+nQp -----END PGP SIGNATURE-----
