RHSA-2025:19088MediumCVSS 6.5

Red Hat Security Advisory: A Subscription Management tool for finding and reporting Red Hat product usage

Published
October 23, 2025
Last Modified
September 1, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2025-6395 — gnutls: NULL pointer dereference in _gnutls_figure_common_ciphersuite() CVE-2025-32988 — gnutls: Vulnerability in GnuTLS otherName SAN export CVE-2025-32989 — gnutls: Vulnerability in GnuTLS SCT extension parsing CVE-2025-32990 — gnutls: Vulnerability in GnuTLS certtool template parsing CVE-2025-53905 — vim: Vim path traversial CVE-2025-53906 — vim: Vim path traversal

🎯 Affected products5

  • Red Hat Discovery 2
  • registry.redhat.io/discovery/discovery-server-rhel9@sha256:54d0aab9e86766954949e7a5a11fb29b6b1c463ebb5ba0fb46b2d0f108753208_amd64 as a component of Red Hat Discovery 2
  • registry.redhat.io/discovery/discovery-server-rhel9@sha256:f4f0ef1497a7cde32f6507f6805050a33ecb95b93bb7ad6bd0544edd3ef19af2_arm64 as a component of Red Hat Discovery 2
  • registry.redhat.io/discovery/discovery-ui-rhel9@sha256:435ba9959b793d46a63a74c343bb8c3ff68350496afec12cc5e894dfc40b7648_arm64 as a component of Red Hat Discovery 2
  • registry.redhat.io/discovery/discovery-ui-rhel9@sha256:4784c2680572f9d091fcfb8c593d5424c0fcd8ea9cd51d25ddaf2f72abc7da65_amd64 as a component of Red Hat Discovery 2

✅ Remediation

The containers required to run Discovery can be installed through discovery-installer RPM. See the official documentation for more details. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Currently, no mitigation is available for this vulnerability.

🔗 References (10)