CVE-2017-7507: GNU Gnutls

High severity, CVSS 7.5. EPSS: 3.4% chance of exploitation in the next 30 days.

GnuTLS version 3.5.12 and earlier is vulnerable to a NULL pointer dereference while decoding a status response TLS extension with valid contents. This could lead to a crash of the GnuTLS server application.

Affected products

  • GNU Gnutls: up to and including 3.5.12

Published 2017-06-16. Last modified 2026-06-17.