Alerts This Week
Warning Icon 1 758
Alerts This Week
Warning Icon 1 758

SUSE Linux Enterprise Server gnutls Moderate DoS Buffer Overflow 20984-1

suse
Calendar Grey April 9, 2026
Dist Suse Esm H88
SUSE updates gnutls to fix two issues, including DoS and buffer overflow vulnerabilities ensuring system stability.
An update that solves two vulnerabilities, contains two features and has one fix can now be installed.

Summary

## This update for gnutls fixes the following issues: * CVE-2025-14831: Fixed DoS via excessive resource consumption during certificate verification. (bsc#1257960) * CVE-2025-9820: Fixed a buffer overflow in gnutls_pkcs11_token_init. (bsc#1254132) * Add the functionality to allow to specify the hash algorithm for the PSK. This fixes a bug in the current implementation where the binder is always calculated with SHA256. (bsc#1258083, jsc#PED-15752, jsc#PED-15753) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server - BCI 16.0 zypper in -t patch SUSE-SLES-16.0-464=1 ## Package List:

References

* bsc#1254132

* bsc#1257960

* bsc#1258083

* jsc#PED-15752

* jsc#PED-15753

Cross-

* CVE-2025-14831

* CVE-2025-9820

CVSS scores:

* CVE-2025-14831 ( SUSE ): 6.9

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

* CVE-2025-14831 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

* CVE-2025-14831 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

* CVE-2025-9820 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

* CVE-2025-9820 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected Products:

* SUSE Linux Enterprise Server - BCI 16.0

An update that solves two vulnerabilities, contains two features and has one fix

can now be installed.

##

* https://www.suse.com/security/cve/CVE-2025-14831.html

Announcement ID: SUSE-SU-2026:20984-1
Release Date: 2026-03-30T14:36:07Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here