NULL pointer dereference in OpenSSL - CVE-2021-3449

 

NULL pointer dereference in OpenSSL - CVE-2021-3449

Published: March 25, 2021 / Updated: June 7, 2024


Vulnerability identifier: #VU51733
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3449
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error when processing TLSv1.2 renegotiations. A remote attacker can send a maliciously crafted renegotiation ClientHello message, which omits the signature_algorithms extension but includes a signature_algorithms_cert extension, trigger a NULL pointer dereference error and crash the server.

Affected software

OpenSSL
Arch Linux
Gentoo Linux
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE MicroOS
SUSE Enterprise Storage
Fedora
SonicOS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Module for Web Scripting
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise Software Development Kit
FreeBSD
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
Ubuntu
openEuler
JBoss Core Services
IBM Security Verify Bridge
IBM Netcool Agile Service Manager
Red Hat Advanced Cluster Management for Kubernetes
IBM Cloud Transformation Advisor
IBM Security Guardium Insights
EasyApache
Tenable Nessus
IBM Integration Bus
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Safer Payments
PowerProtect Data Manager
IBM Security Verify Gateway
cflinuxfs3
APM Edge
HP-UX OpenSSL
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
openssl (Debian package)
imgbased (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
redhat-release-virtualization-host (Red Hat package)
redhat-virtualization-host (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
scap-security-guide (Red Hat package)
isl (Red Hat package)
libmpc (Red Hat package)
openssl (Red Hat package)
libopenssl1_1-debuginfo-32bit
libopenssl-1_1-devel
libopenssl-1_1-devel-32bit
openssl-1_1-debugsource
openssl-1_1-debuginfo
openssl-1_1
libopenssl1_1-debuginfo
libopenssl1_1-32bit
libopenssl1_1
libopenssl1_1-hmac
libopenssl1_1-hmac-32bit
libopenssl1_1-32bit-debuginfo
openssl-debugsource
openssl-libs
openssl-devel
openssl-debuginfo
openssl-help
openssl
openssl11
libssl1.1 (Ubuntu package)
boost (Red Hat package)
zip (Red Hat package)
libxcrypt (Red Hat package)
make (Red Hat package)
gcc (Red Hat package)
dyninst (Red Hat package)
postgresql-10 (Ubuntu package)
npm10
nodejs10-docs
nodejs10-devel
nodejs10
nodejs10-debugsource
nodejs10-debuginfo
postgresql-12 (Ubuntu package)
nodejs12-docs
nodejs12
nodejs12-debuginfo
nodejs12-debugsource
nodejs12-devel
npm12
postgresql-13 (Ubuntu package)
tbb (Red Hat package)
Red Hat OpenShift Serverless
Windows Container Support for Red Hat OpenShift
Red Hat Virtualization
Cloud Pak for Security (CP4S)
Red Hat OpenShift Jaeger
SonicWall Capture Client
Red Hat Virtualization Host
Red Hat OpenShift Container Platform
Nessus Network Monitor
IBM DataPower Gateway
TippingPoint Threat Protection System
MySQL Server
Tenable.sc
IBM Security Verify Access
SMA 100
IBM App Connect Enterprise
Visual Studio
SINEC INS
Dell EMC Storage Monitoring and Reporting (SMR)
JBoss Web Server
IBM Cognos Analytics

How to mitigate CVE-2021-3449

Install update from vendor's website.

OpenSSL - update to 1.1.1k
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - update to 0.4.10-20.jbcs.el7
cflinuxfs3 - update to 0.232.0
Red Hat OpenShift Serverless - addressed in versions 1.10.2, 1.14.0
APM Edge - update to 4.0
jbcs-httpd24-openssl-chil (Red Hat package) - update to 1.0.0-5.jbcs.el7
IBM Netcool Agile Service Manager - update to 1.1.13
openssl (Debian package) - update to 1.1.1d-0+deb10u6
imgbased (Red Hat package) - update to 1.2.18-0.1.el8ev
Cloud Pak for Security (CP4S) - update to 1.8.0.0
jbcs-httpd24-mod_http2 (Red Hat package) - update to 1.15.7-14.jbcs.el7
Red Hat OpenShift Jaeger - addressed in versions 1.17.9, 1.20.4
jbcs-httpd24-nghttp2 (Red Hat package) - update to 1.39.2-37.jbcs.el7
Windows Container Support for Red Hat OpenShift - update to 2.0.1
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.0.10, 2.1.6, 2.2.2
jbcs-httpd24-mod_md (Red Hat package) - update to 2.0.8-33.jbcs.el7
jbcs-httpd24-httpd (Red Hat package) - update to 2.4.37-70.jbcs.el7
jbcs-httpd24-mod_security (Red Hat package) - update to 2.9.2-60.GA.jbcs.el7
IBM Security Guardium Insights - update to 3.0.1
SonicWall Capture Client - update to 3.6.24
EasyApache - addressed in versions 4 2021-3-31, 4 2021-4-28
redhat-release-virtualization-host (Red Hat package) - update to 4.4.5-4.el8ev
redhat-virtualization-host (Red Hat package) - update to 4.4.5-20210330.0.el8_3
Red Hat OpenShift Container Platform - update to 4.6.26
Nessus Network Monitor - update to 5.13.1
MySQL Server - addressed in versions 5.7.34, 8.0.24
Tenable.sc - update to 5.18.0
SonicOS - update to 7.0.1-R1456
Tenable Nessus - update to 8.13.2
IBM DataPower Gateway - addressed in versions 10.0.1.4, 10.0.3.0
SMA 100 - update to 10.2.1.0-17sv
IBM App Connect Enterprise - update to 11.0.0.13
HP-UX OpenSSL - update to A.01.01.01l.001
scap-security-guide (Red Hat package) - update to 0.1.50-1.el8ev
isl (Red Hat package) - update to 0.16.1-6.el8
SINEC INS - update to 1.0.1.1
libmpc (Red Hat package) - update to 1.0.2-9.el8
openssl (Red Hat package) - addressed in versions 1.1.1c-5.el8_1, 1.1.1c-18.el8_2, 1.1.1g-15.el8_3
libopenssl1_1-debuginfo-32bit - update to 1.1.1d-2.33.1
libopenssl-1_1-devel - addressed in versions 1.1.1d-2.33.1, 1.1.1d-11.20.1
libopenssl-1_1-devel-32bit - update to 1.1.1d-2.33.1
openssl-1_1-debugsource - addressed in versions 1.1.1d-2.33.1, 1.1.1d-11.20.1
openssl-1_1-debuginfo - addressed in versions 1.1.1d-2.33.1, 1.1.1d-11.20.1
openssl-1_1 - addressed in versions 1.1.1d-2.33.1, 1.1.1d-11.20.1
libopenssl1_1-debuginfo - addressed in versions 1.1.1d-2.33.1, 1.1.1d-11.20.1
libopenssl1_1-32bit - addressed in versions 1.1.1d-2.33.1, 1.1.1d-11.20.1
libopenssl1_1 - addressed in versions 1.1.1d-2.33.1, 1.1.1d-11.20.1
libopenssl1_1-hmac - update to 1.1.1d-11.20.1
libopenssl1_1-hmac-32bit - update to 1.1.1d-11.20.1
libopenssl1_1-32bit-debuginfo - update to 1.1.1d-11.20.1
openssl-debugsource - update to 1.1.1f-10
openssl-libs - update to 1.1.1f-10
openssl-devel - update to 1.1.1f-10
openssl-debuginfo - update to 1.1.1f-10
openssl-help - update to 1.1.1f-10
openssl - update to 1.1.1f-10
openssl11 - update to 1.1.1g-3.el7
openssl - update to 1.1.1k-1.fc34
libssl1.1 (Ubuntu package) - addressed in versions 1.1.1f-1ubuntu2.3, 1.1.1f-1ubuntu4.3, 1.1.1-1ubuntu2.1~18.04.9
boost (Red Hat package) - update to 1.66.0-10.el8
zip (Red Hat package) - update to 3.0-23.el8
JBoss Web Server - addressed in versions 3.1 SP12, 5.4.2
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.0.0
libxcrypt (Red Hat package) - update to 4.1.1-4.el8
make (Red Hat package) - update to 4.2.1-10.el8
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.6.0.0
IBM Safer Payments - addressed in versions 6.1.0.08, 6.2.1.03
gcc (Red Hat package) - update to 8.3.1-5.1.el8
dyninst (Red Hat package) - update to 10.1.0-4.el8
postgresql-10 (Ubuntu package) - update to 10.18-0ubuntu0.18.04.1
npm10 - addressed in versions 10.24.1-1.36.1, 10.24.1-1.39.1
nodejs10-docs - addressed in versions 10.24.1-1.36.1, 10.24.1-1.39.1
nodejs10-devel - addressed in versions 10.24.1-1.36.1, 10.24.1-1.39.1
nodejs10 - addressed in versions 10.24.1-1.36.1, 10.24.1-1.39.1
nodejs10-debugsource - addressed in versions 10.24.1-1.36.1, 10.24.1-1.39.1
nodejs10-debuginfo - addressed in versions 10.24.1-1.36.1, 10.24.1-1.39.1
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2
postgresql-12 (Ubuntu package) - update to 12.8-0ubuntu0.20.04.1
nodejs12-docs - addressed in versions 12.22.2-1.32.1, 12.22.2-4.16.1
nodejs12 - addressed in versions 12.22.2-1.32.1, 12.22.2-4.16.1
nodejs12-debuginfo - addressed in versions 12.22.2-1.32.1, 12.22.2-4.16.1
nodejs12-debugsource - addressed in versions 12.22.2-1.32.1, 12.22.2-4.16.1
nodejs12-devel - addressed in versions 12.22.2-1.32.1, 12.22.2-4.16.1
npm12 - addressed in versions 12.22.2-1.32.1, 12.22.2-4.16.1
postgresql-13 (Ubuntu package) - update to 13.4-0ubuntu0.21.04.1
PowerProtect Data Manager - update to 19.19.0-15
tbb (Red Hat package) - update to 2018.2-9.el8

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins