Use-after-free in GnuTLS - CVE-2021-20232
Published: March 14, 2021
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The
vulnerability exists due to a use-after-free error in client_send_params in lib/ext/pre_shared_key.c. A remote attacker can trick the victim to connect
to a malicious server using a large Client Hello message over TLS 1.3,
trigger a use-after-free error and crash the application or execute
arbitrary code on the system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
Arch Linux
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE MicroOS
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Module for Basesystem
openEuler
Ubuntu
Fedora
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Cloud Pak for Security (CP4S)
Ansible Automation Platform
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Red Hat OpenStack
nettle (Red Hat package)
gnutls (Red Hat package)
gnutls-debugsource
libgnutls30-hmac-32bit
libgnutls30-32bit-debuginfo
libgnutls30-32bit
libgnutlsxx28-debuginfo
libgnutlsxx28
libgnutlsxx-devel
libgnutls30-hmac
libgnutls30-debuginfo
libgnutls30
libgnutls-devel
gnutls-debuginfo
gnutls
libgnutls30 (Ubuntu package)
gnutls-devel
gnutls-help
gnutls-utils
gnutls-dane
gnutls-c++
Red Hat OpenShift Serverless
OpenShift Virtualization
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
RecoverPoint for VMs
Dell EMC VxRail Appliance
How to mitigate CVE-2021-20232
Migration Toolkit for Containers - addressed in versions 1.5.4, 1.7.4
Cloud Pak for Security (CP4S) - update to 1.10.7.0
nettle (Red Hat package) - update to 3.4.1-7.el8
gnutls (Red Hat package) - update to 3.6.16-4.el8
Red Hat OpenShift Container Platform - addressed in versions 4.11.0, 4.11.45
Red Hat OpenShift Serverless - update to 1.20.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
gnutls-debugsource - addressed in versions 3.6.7-6.40.2, 3.6.7-14.10.2
libgnutls30-hmac-32bit - addressed in versions 3.6.7-6.40.2, 3.6.7-14.10.2
libgnutls30-32bit-debuginfo - addressed in versions 3.6.7-6.40.2, 3.6.7-14.10.2
libgnutls30-32bit - addressed in versions 3.6.7-6.40.2, 3.6.7-14.10.2
libgnutlsxx28-debuginfo - addressed in versions 3.6.7-6.40.2, 3.6.7-14.10.2
libgnutlsxx28 - addressed in versions 3.6.7-6.40.2, 3.6.7-14.10.2
libgnutlsxx-devel - addressed in versions 3.6.7-6.40.2, 3.6.7-14.10.2
libgnutls30-hmac - addressed in versions 3.6.7-6.40.2, 3.6.7-14.10.2
libgnutls30-debuginfo - addressed in versions 3.6.7-6.40.2, 3.6.7-14.10.2
libgnutls30 - addressed in versions 3.6.7-6.40.2, 3.6.7-14.10.2
libgnutls-devel - addressed in versions 3.6.7-6.40.2, 3.6.7-14.10.2
gnutls-debuginfo - addressed in versions 3.6.7-6.40.2, 3.6.7-14.10.2
gnutls - addressed in versions 3.6.7-6.40.2, 3.6.7-14.10.2
libgnutls30 (Ubuntu package) - update to 3.6.13-2ubuntu1.6
gnutls-devel - update to 3.6.14-7
gnutls-help - update to 3.6.14-7
gnutls-debuginfo - update to 3.6.14-7
gnutls-debugsource - update to 3.6.14-7
gnutls - update to 3.6.14-7
gnutls-utils - update to 3.6.16-5.0.1
gnutls-devel - update to 3.6.16-5.0.1
gnutls-dane - update to 3.6.16-5.0.1
gnutls-c++ - update to 3.6.16-5.0.1
gnutls - update to 3.6.16-5.0.1
gnutls - update to 3.7.1-2.fc34
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
OpenShift Virtualization - update to 4.11.0
Dell EMC Unity XT Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity VSA Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity Operating Environment (OE) - update to 5.1.2.0.5.007
RecoverPoint for VMs - update to 6.0.SP1.P1
Dell EMC VxRail Appliance - update to 7.0.240
Red Hat OpenStack - update to 16.2
External References
Related Security Bulletins
- Use-after-free in gnutls
- Arch Linux update for gnutls
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Red Hat Enterprise Linux 8 update for gnutls and nettle
- Multiple vulnerabilities in Dell EMC Unity
- Ubuntu update for gnutls28
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC) 1.7
- Multiple vulnerabilities in OpenShift Virtualization
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- SUSE update for gnutls
- SUSE update for gnutls
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 2.4
- openEuler update for gnutls
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 3.67
- Multiple vulnerabilities in Red Hat OpenShift Serverless 1.20
- Multiple vulnerabilities in Red Hat OpenStack 16.2 packages
- Multiple vulnerabilities in Migration Toolkit for Containers 1.5
- Fedora 34 update for gnutls
- Multiple vulnerabilities in Dell RecoverPoint for Virtual Machines
- Anolis OS update for gnutls
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.2