Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

SUSE Linux Micro gnutls Moderate DoS CVE-2025-14831 Advisory 2026-20708-1

suse
Calendar Grey March 18, 2026
Dist Suse Esm H88
Addressing security issues with gnutls, the latest SUSE patch resolves moderate vulnerabilities and enhances performance features.
An update that solves one vulnerability, contains two features and has one fix can now be installed.

Summary

## This update for gnutls fixes the following issues: Add the functionality to allow to specify the hash algorithm for the PSK. This fixes a bug in the current implementation where the binder is always calculated with SHA256. * (bsc#1258083, jsc#PED-15752, jsc#PED-15753) * lib/psk: Add gnutls_psk_allocate_{client,server}_credentials2 * tests/psk-file: Add testing for _credentials2 functions * lib/psk: add null check for binder algo * pre_shared_key: fix memleak when retrying with different binder algo * pre_shared_key: add null check on pskcred Security fix: * CVE-2025-14831: DoS via excessive resource consumption during certificate verification (bsc#1257960) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".

References

* bsc#1257960

* bsc#1258083

* jsc#PED-15752

* jsc#PED-15753

Cross-

* CVE-2025-14831

CVSS scores:

* CVE-2025-14831 ( SUSE ): 6.9

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

* CVE-2025-14831 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

* CVE-2025-14831 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected Products:

* SUSE Linux Micro 6.0

An update that solves one vulnerability, contains two features and has one fix

can now be installed.

##

* https://www.suse.com/security/cve/CVE-2025-14831.html

* https://bugzilla.suse.com/show_bug.cgi?id=1257960

* https://bugzilla.suse.com/show_bug.cgi?id=1258083

* https://jira.suse.com/browse/PED-15752

* https://jira.suse.com/browse/PED-15753

Announcement ID: SUSE-SU-2026:20708-1
Release Date: 2026-03-06T12:16:00Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here