Vulnerability CVE-2021-4209: Information

Description

A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances.

Severity: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Published: Aug. 24, 2022
Modified: Oct. 27, 2022
Error type identifier: CWE-476

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
gnutls30sisyphus3.7.6-alt13.8.4-alt1ALT-PU-2022-2183-1303294Fixed
gnutls30sisyphus_e2k3.7.6-alt13.8.4-alt1ALT-PU-2022-5470-1-Fixed
gnutls30sisyphus_riscv643.7.6-alt13.8.4-alt1ALT-PU-2022-5385-1-Fixed
gnutls30p103.6.16-alt63.6.16-alt6ALT-PU-2024-7207-2345961Fixed
gnutls30p10_e2k3.6.16-alt63.6.16-alt6ALT-PU-2024-7454-1-Fixed
gnutls30p93.6.16-alt63.6.16-alt6ALT-PU-2024-7788-2345962Fixed
gnutls30c10f13.6.16-alt63.6.16-alt6ALT-PU-2024-7758-3348084Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:*
      End excliding
      3.7.3

      Configuration 2

      cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*

      cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*

      Configuration 4

      cpe:2.3:a:netapp:hci_bootstrap_os:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*