CVE-2022-2509: Double Free
A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of pkcs7 signatures in gnutlspkcs7verify function.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-2509?
CVE-2022-2509 is a vulnerability found in gnutls. It is a security flaw that occurs due to a double free error during the verification of pkcs7 signatures in the gnutls_pkcs7_verify function.
What is the severity of CVE-2022-2509?
CVE-2022-2509 has a severity level of high.
Which software is affected by CVE-2022-2509?
CVE-2022-2509 affects Gnu Gnutls, Redhat Enterprise Linux 8.0 and 9.0, Fedoraproject Fedora 35, and Debian Debian Linux 10.0 and 11.0.
How can I fix CVE-2022-2509?
To fix CVE-2022-2509, you should update the gnutls28 package to version 3.7.7 or above on affected systems.
Where can I find more information about CVE-2022-2509?
You can find more information about CVE-2022-2509 at the following references: [Red Hat](https://access.redhat.com/security/cve/CVE-2022-2509), [Debian LTS Announcement](https://lists.debian.org/debian-lts-announce/2022/08/msg00002.html), [Fedora Project](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6FL27JS3VM74YEQU7PGB62USO3KSBYZX/)