CVE-2015-3308: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 3.9% chance of exploitation in the next 30 days.

Double free vulnerability in lib/x509/x509_ext.c in GnuTLS before 3.3.14 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted CRL distribution point.

Affected products

  • Canonical Ubuntu Linux: version 15.04 only
  • GNU Gnutls: up to and including 3.3.13

Published 2015-09-02. Last modified 2026-06-17.