NULL pointer dereference in OpenSSL - CVE-2021-23841
Published: February 17, 2021 / Updated: October 2, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within the X509_issuer_and_serial_hash() function when parsing the issuer field in the X509 certificate. A remote attacker can supply a specially crafted certificate, trigger a NULL pointer dereference error and perform a denial of service (DoS) attack.
Affected software
Arch Linux
Gentoo Linux
Amazon Linux AMI
SUSE Manager Retail Branch Server
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Proxy
SUSE MicroOS
SUSE Enterprise Storage
SUSE OpenStack Cloud
Fedora
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
CentOS
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
IBM AIX
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
HPE Helion Openstack
SUSE OpenStack Cloud Crowbar
FreeBSD
macOS
SUSE Linux Enterprise Server
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Module for Legacy Software
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Ubuntu
iPadOS
Apple iOS
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
Junos OS
openEuler
Brocade Fabric OS
IBM Security Verify Bridge
Red Hat Advanced Cluster Management for Kubernetes
EasyApache
IBM Rational Build Forge
InfoSphere Master Data Management
IBM MaaS360 Cloud Extender Agent
Red Hat Advanced Cluster Security for Kubernetes
IBM Aspera Orchestrator
IBM Safer Payments
Engineering Workflow Management
NetWorker
PowerProtect Data Manager
IBM Security Verify Gateway
APM Edge
Telemetry Dashboard
Oracle Business Intelligence Enterprise Edition
Liquidware
Citrix Workspace App
Webex App VDI
HP-UX OpenSSL
IBM Aspera Shares
IBM MaaS360 Base Module
IBM MaaS360 Ceriticate Integration Module
IBM Aspera Console
Flex System Fabric EN4093/EN4093R 10Gb Scalable Switch
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
openssl (Red Hat package)
openssl (Debian package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-apr (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
libopenssl-devel
libopenssl0_9_8
libopenssl0_9_8-hmac
openssl
openssl-doc
libopenssl0_9_8-32bit
libopenssl0_9_8-hmac-32bit
openssl-debugsource
openssl-debuginfo
libopenssl0_9_8-debuginfo
compat-openssl098-debugsource
libopenssl0_9_8-debuginfo-32bit
openssl1-debugsource
libopenssl1_0_0-32bit
openssl1-debuginfo
libopenssl1_0_0-x86
openssl1-doc
openssl1
libopenssl1-devel
libopenssl1_0_0
libssl1.0.0 (Ubuntu package)
libopenssl1_0_0-debuginfo-32bit
libopenssl1_0_0-debuginfo
libopenssl1_0_0-hmac
libopenssl1_0_0-hmac-32bit
openssl-1_0_0-debugsource
openssl-1_0_0-doc
openssl-1_0_0-debuginfo
openssl-1_0_0
libopenssl-1_0_0-devel
libopenssl10-debuginfo
libopenssl10
openssl-1_1-debuginfo
libopenssl-1_1-devel
libopenssl1_1
libopenssl1_1-debuginfo
libopenssl1_1-hmac
openssl-1_1
openssl-1_1-debugsource
libopenssl1_1-32bit
libopenssl1_1-32bit-debuginfo
libopenssl1_1-hmac-32bit
libopenssl-1_1-devel-32bit
libopenssl1_1-debuginfo-32bit
openssl-help
openssl-devel
openssl-libs
openssl11
libssl1.1 (Ubuntu package)
edk2 (Red Hat package)
IBM Integrated Analytics System
IBM Aspera Faspex for Windows
IBM Aspera Faspex for Linux
Cloud Pak for Security (CP4S)
Nessus Agent
IBM Cloud Pak System
JBoss Core Services
IBM VIOS
Nessus Network Monitor
VMware Horizon Client
MySQL Server
MySQL Enterprise Monitor
LANTIME Operating System Firmware (LTOS)
IBM Security Guardium
Apple Safari
Cisco Jabber
Oracle GraalVM Enterprise Edition
Cisco Webex Meetings
SINEC INS
Dell EMC Storage Monitoring and Reporting (SMR)
IBM MaaS360 VPN Module
Engineering Lifecycle Management
IBM Flex System CN4093 10Gb Converged Scalable Switch
IBM Flex System Fabric SI4093 GbFSIM 10Gb Scalable Switch
IBM Flex System EN2092 1Gb Ethernet Scalable Switch
IBM Cognos Analytics
Juniper Junos Space
How to mitigate CVE-2021-23841
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-22.el8jbcs, 0.4.10-22.jbcs.el7
APM Edge - update to 4.0
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-7.el8jbcs, 1.0.0-7.jbcs.el7
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
openssl (Red Hat package) - addressed in versions 1.0.2k-22.el7_9, 1.1.1k-4.el8
openssl (Debian package) - update to 1.1.1d-0+deb10u5
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-84.el8jbcs, 1.6.1-84.jbcs.el7
jbcs-httpd24-apr (Red Hat package) - addressed in versions 1.6.3-107.el8jbcs, 1.6.3-107.jbcs.el7
Cloud Pak for Security (CP4S) - update to 1.10.7.0
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.7-21.el8jbcs, 1.15.7-21.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package) - addressed in versions 1.39.2-39.el8jbcs, 1.39.2-39.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.0.8-40.el8jbcs, 2.0.8-40.jbcs.el7
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.1.12, 2.2.2, 2.2.10, 2.3.3
IBM Cloud Pak System - update to 2.3.3.5
JBoss Core Services - update to 2.4.37 SP10
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-78.el8jbcs, 2.4.37-78.jbcs.el7
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.2-67.GA.el8jbcs, 2.9.2-67.GA.jbcs.el7
EasyApache - update to 4 2021-2-24
Nessus Network Monitor - update to 5.13.1
MySQL Server - addressed in versions 5.7.34, 8.0.24
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
LANTIME Operating System Firmware (LTOS) - addressed in versions 6.24.028, 7.02.003
Nessus Agent - update to 8.2.3
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.78.0-2.el8jbcs, 7.78.0-2.jbcs.el7
IBM Rational Build Forge - update to 8.0.0.24
macOS - update to 11.4 20F71
iPadOS - update to 14.6 18F72
Apple Safari - update to 14.1.1
Apple iOS - update to 14.6 18F72
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Junos OS - addressed in versions 18.4R2-S10, 19.2R1-S9, 19.2R3-S5, 19.3R3-S5, 19.4R3-S7, 20.1R3-S3, 20.2R3-S4, 20.3R3-S2, 20.4R3-S1, 21.1R3-S1, 21.2R2-S1, 21.2R3, 21.3R2, 21.4R1
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
HP-UX OpenSSL - update to A.01.01.01l.001
libopenssl-devel - addressed in versions 0.9.8j-0.106.37.1, 1.0.2j-60.66.1
libopenssl0_9_8 - addressed in versions 0.9.8j-0.106.37.1, 0.9.8j-106.24.1
libopenssl0_9_8-hmac - update to 0.9.8j-0.106.37.1
openssl - addressed in versions 0.9.8j-0.106.37.1, 1.0.2j-60.66.1
openssl-doc - addressed in versions 0.9.8j-0.106.37.1, 1.0.2j-60.66.1
libopenssl0_9_8-32bit - addressed in versions 0.9.8j-0.106.37.1, 0.9.8j-106.24.1
libopenssl0_9_8-hmac-32bit - update to 0.9.8j-0.106.37.1
openssl-debugsource - addressed in versions 0.9.8j-0.106.37.1, 1.0.2j-60.66.1
openssl-debuginfo - addressed in versions 0.9.8j-0.106.37.1, 1.0.2j-60.66.1
libopenssl0_9_8-debuginfo - update to 0.9.8j-106.24.1
compat-openssl098-debugsource - update to 0.9.8j-106.24.1
libopenssl0_9_8-debuginfo-32bit - update to 0.9.8j-106.24.1
SINEC INS - update to 1.0 SP2
openssl1-debugsource - update to 1.0.1g-0.58.33.1
libopenssl1_0_0-32bit - addressed in versions 1.0.1g-0.58.33.1, 1.0.2j-60.66.1, 1.0.2p-3.36.1
openssl1-debuginfo - update to 1.0.1g-0.58.33.1
libopenssl1_0_0-x86 - update to 1.0.1g-0.58.33.1
openssl1-doc - update to 1.0.1g-0.58.33.1
openssl1 - update to 1.0.1g-0.58.33.1
libopenssl1-devel - update to 1.0.1g-0.58.33.1
libopenssl1_0_0 - addressed in versions 1.0.1g-0.58.33.1, 1.0.2j-60.66.1, 1.0.2p-3.36.1, 1.0.2p-3.37.1
libssl1.0.0 (Ubuntu package) - addressed in versions 1.0.1f-1ubuntu2.27+esm2, 1.0.1-4ubuntu5.45, 1.0.2g-1ubuntu4.19, 1.0.2n-1ubuntu5.6
libopenssl1_0_0-debuginfo-32bit - addressed in versions 1.0.2j-60.66.1, 1.0.2p-3.36.1
libopenssl1_0_0-debuginfo - addressed in versions 1.0.2j-60.66.1, 1.0.2p-3.36.1, 1.0.2p-3.37.1
libopenssl1_0_0-hmac - addressed in versions 1.0.2j-60.66.1, 1.0.2p-3.36.1
libopenssl1_0_0-hmac-32bit - addressed in versions 1.0.2j-60.66.1, 1.0.2p-3.36.1
openssl-1_0_0-debugsource - addressed in versions 1.0.2p-3.36.1, 1.0.2p-3.37.1
openssl-1_0_0-doc - update to 1.0.2p-3.36.1
openssl-1_0_0-debuginfo - addressed in versions 1.0.2p-3.36.1, 1.0.2p-3.37.1
openssl-1_0_0 - addressed in versions 1.0.2p-3.36.1, 1.0.2p-3.37.1
libopenssl-1_0_0-devel - addressed in versions 1.0.2p-3.36.1, 1.0.2p-3.37.1
libopenssl10-debuginfo - update to 1.0.2p-3.37.1
libopenssl10 - update to 1.0.2p-3.37.1
openssl-1_1-debuginfo - addressed in versions 1.1.0i-4.57.1, 1.1.0i-14.15.1, 1.1.1d-2.30.1, 1.1.1d-11.17.1
libopenssl-1_1-devel - addressed in versions 1.1.0i-4.57.1, 1.1.0i-14.15.1, 1.1.1d-2.30.1, 1.1.1d-11.17.1
libopenssl1_1 - addressed in versions 1.1.0i-4.57.1, 1.1.0i-14.15.1, 1.1.1d-2.30.1, 1.1.1d-11.17.1
libopenssl1_1-debuginfo - addressed in versions 1.1.0i-4.57.1, 1.1.0i-14.15.1, 1.1.1d-2.30.1, 1.1.1d-11.17.1
libopenssl1_1-hmac - addressed in versions 1.1.0i-4.57.1, 1.1.0i-14.15.1, 1.1.1d-11.17.1
openssl-1_1 - addressed in versions 1.1.0i-4.57.1, 1.1.0i-14.15.1, 1.1.1d-2.30.1, 1.1.1d-11.17.1
openssl-1_1-debugsource - addressed in versions 1.1.0i-4.57.1, 1.1.0i-14.15.1, 1.1.1d-2.30.1, 1.1.1d-11.17.1
libopenssl1_1-32bit - addressed in versions 1.1.0i-4.57.1, 1.1.0i-14.15.1, 1.1.1d-2.30.1, 1.1.1d-11.17.1
libopenssl1_1-32bit-debuginfo - addressed in versions 1.1.0i-4.57.1, 1.1.0i-14.15.1, 1.1.1d-11.17.1
libopenssl1_1-hmac-32bit - addressed in versions 1.1.0i-4.57.1, 1.1.0i-14.15.1, 1.1.1d-11.17.1
libopenssl-1_1-devel-32bit - addressed in versions 1.1.0i-14.15.1, 1.1.1d-2.30.1
libopenssl1_1-debuginfo-32bit - update to 1.1.1d-2.30.1
openssl-help - update to 1.1.1f-4
openssl-debugsource - update to 1.1.1f-4
openssl-debuginfo - update to 1.1.1f-4
openssl-devel - update to 1.1.1f-4
openssl-libs - update to 1.1.1f-4
openssl - update to 1.1.1f-4
openssl11 - update to 1.1.1k-1.el7
libssl1.1 (Ubuntu package) - addressed in versions 1.1.1f-1ubuntu2.2, 1.1.1f-1ubuntu4.2, 1.1.1-1ubuntu2.1~18.04.8
IBM Aspera Shares - update to 1.9.15
IBM MaaS360 VPN Module - update to 2.105.300.005
IBM MaaS360 Base Module - update to 2.105.300.005
IBM MaaS360 Ceriticate Integration Module - update to 2.105.300.005
IBM MaaS360 Cloud Extender Agent - update to 2.105.300.005
IBM Aspera Console - update to 3.4.2
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
IBM Aspera Orchestrator - update to 4.0.1.2b9681
IBM Aspera Faspex for Windows - update to 4.4.2
IBM Aspera Faspex for Linux - update to 4.4.2
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.6.0.0
IBM Safer Payments - addressed in versions 5.7.0.13, 6.0.0.10, 6.1.0.08, 6.2.1.03
Engineering Lifecycle Management - addressed in versions 7.0.1 iFix022, 7.0.2 iFix023
Engineering Workflow Management - addressed in versions 7.0.1 iFix022, 7.0.2 iFix023
Brocade Fabric OS - addressed in versions 7.4.2j, 8.2.0 CBN5, 8.2.3c, 9.0.1e, 9.1.1
IBM Flex System CN4093 10Gb Converged Scalable Switch - update to 7.8.31.0
Flex System Fabric EN4093/EN4093R 10Gb Scalable Switch - update to 7.8.31.0
IBM Flex System Fabric SI4093 GbFSIM 10Gb Scalable Switch - update to 7.8.31.0
IBM Flex System EN2092 1Gb Ethernet Scalable Switch - update to 7.8.31.0
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2
NetWorker - update to 19.10.0.0
PowerProtect Data Manager - update to 19.19.0-15
Juniper Junos Space - update to 22.1R1
edk2 (Red Hat package) - update to 20210527gite1999b264f1f-3.el8
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenSSL
- Debian update for openssl
- Amazon Linux AMI update for openssl
- EasyApache update for OpenSSL
- Arch Linux update for openssl
- Multiple vulnerabilities in Tenable Nessus Agent
- Gentoo update for OpenSSL
- IBM AIX update for OpenSSL
- IBM VIOS update for OpenSSL
- Multiple vulnerabilities in MySQL Server
- Multiple vulnerabilities in MySQL Enterprise Monitor
- Multiple vulnerabilities in Oracle GraalVM Enterprise Edition
- Multiple vulnerabilities in Nessus Network Monitor
- Multiple vulnerabilities in Apple macOS Big Sur
- Multiple vulnerabilities in Apple iOS and iPadOS
- Multiple vulnerabilities in Apple Safari
- FreeBSd update for OpenSSL
- Red Hat Enterprise Linux 7 update for openssl
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.3
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.1
- Multiple vulnerabilities in Red Hat JBoss Core Services Apache HTTP Server
- Red Hat Enterprise Linux 8 update for openssl
- CentOS 7 update for openssl
- Multiple vulnerabilities in Hitachi Energy APM Edge
- Multiple vulnerabilities in IBM Integrated Analytics System
- IBM Security Guardium update for OpenSSL
- Ubuntu update for openssl
- Ubuntu update for openssl
- Junos OS update for OpenSSL
- Multiple vulnerabilities in Junos Space
- Multiple vulnerabilities in IBM InfoSphere Master Data Management
- Multiple vulnerabilities in IBM Cloud Pak System third-party components
- Multiple vulnerabilities in IBM Aspera Console and Aspera Shares
- Multiple vulnerabilities in Siemens SINEC INS
- Multiple vulnerabilities in IBM Security Verify products
- Brocade Fabric OS update for OpenSSL
- Multiple vulnerabilities in IBM MaaS360 Cloud Extender and Modules
- Multiple vulnerabilities in IBM Security Verify Bridge
- Multiple vulnerabilities in IBM Aspera Faspex
- Multiple vulnerabilities in Dell Storage Monitoring and Reporting (SMR)
- Red Hat Enterprise Linux 8 update for edk2
- Multiple vulnerabilities in IBM Aspera Orchestrator
- SUSE update for openssl-1_0_0
- SUSE update for openssl-1_1
- SUSE update for openssl-1_1
- SUSE update for openssl-1_1
- SUSE update for openssl-1_1
- SUSE update for openssl-1_0_0
- SUSE update for compat-openssl098
- SUSE update for openssl1
- SUSE update for openssl
- SUSE update for openssl
- Multiple vulnerabilities in HPE HP-UX Using OpenSSL
- Multiple vulnerabilities in IBM Safer Payments
- Multiple vulnerabilities in IBM Engineering Workflow Management (EWM)
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in IBM Rational Build Forge
- Multiple vulnerabilities in Dell Networker
- Multiple vulnerabilities in IBM Cognos Analytics
- openEuler update for openssl
- Multiple vulnerabilities in Dell ThinOS
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 3.67
- Fedora EPEL 7 update for openssl11
- Multiple vulnerabilities in Dell PowerProtect Data Manager
- Multiple vulnerabilities in Meinberg LANTIME firmware
- Multiple vulnerabilities in IBM Flex System switch firmware products
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.2
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.2