CVE-2025-6395: NULL Pointer Dereference
A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite().
AI Analysis
Technical Summary
CVE-2025-6395 is a NULL pointer dereference vulnerability found in the GnuTLS library, specifically in the _gnutls_figure_common_ciphersuite() function. This vulnerability affects GnuTLS versions included in Red Hat Enterprise Linux 9 (>=9.0 <9.9) and 10 (>=10.0 <10.3), as well as an anomalous '=0' version entry. The issue can cause application crashes leading to denial of service (availability impact). Red Hat has issued security advisories RHSA-2025:16115 and RHSA-2025:16116 that provide updated packages fixing this vulnerability. The CVSS v3.1 base score is 6.5 (AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H), reflecting network attack vector, high attack complexity, no privileges required, no user interaction, unchanged scope, no confidentiality impact, low integrity impact, and high availability impact. No exploits are currently known in the wild.
Potential Impact
The vulnerability can cause a NULL pointer dereference resulting in application crashes, leading to denial of service (availability impact). There is no confidentiality impact and only a low integrity impact. No active exploitation has been reported.
Mitigation Recommendations
Red Hat has released official security updates that fix this vulnerability for affected versions of Red Hat Enterprise Linux 9 and 10. Users should apply the updates as described in Red Hat advisories RHSA-2025:16115 and RHSA-2025:16116. The advisories provide detailed instructions and updated package versions. Applying these patches mitigates the vulnerability. No additional mitigation steps are indicated by the vendor.
CVE-2025-6395: NULL Pointer Dereference
Description
A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite().
CVSS v3.1
Score 6.5medium
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-6395 is a NULL pointer dereference vulnerability found in the GnuTLS library, specifically in the _gnutls_figure_common_ciphersuite() function. This vulnerability affects GnuTLS versions included in Red Hat Enterprise Linux 9 (>=9.0 <9.9) and 10 (>=10.0 <10.3), as well as an anomalous '=0' version entry. The issue can cause application crashes leading to denial of service (availability impact). Red Hat has issued security advisories RHSA-2025:16115 and RHSA-2025:16116 that provide updated packages fixing this vulnerability. The CVSS v3.1 base score is 6.5 (AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H), reflecting network attack vector, high attack complexity, no privileges required, no user interaction, unchanged scope, no confidentiality impact, low integrity impact, and high availability impact. No exploits are currently known in the wild.
Potential Impact
The vulnerability can cause a NULL pointer dereference resulting in application crashes, leading to denial of service (availability impact). There is no confidentiality impact and only a low integrity impact. No active exploitation has been reported.
Mitigation Recommendations
Red Hat has released official security updates that fix this vulnerability for affected versions of Red Hat Enterprise Linux 9 and 10. Users should apply the updates as described in Red Hat advisories RHSA-2025:16115 and RHSA-2025:16116. The advisories provide detailed instructions and updated package versions. Applying these patches mitigates the vulnerability. No additional mitigation steps are indicated by the vendor.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- redhat
- Date Reserved
- 2025-06-20T06:26:20.649Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/errata/RHSA-2025:16115","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:16116","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:17181","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:17348","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:17361","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:17415","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:19088","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:22529","vendor":"Red Hat"},{"url":"https://access.redhat.com/security/cve/CVE-2025-6395","vendor":"Red Hat"}]
Threat ID: 686fdcbba83201eaaca87c6b
Added to database: 07/10/2025, 15:31:07 UTC
Last enriched: 07/15/2026, 11:29:50 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 282
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.