Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-6445.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-6445
Upstream
Published
2020-09-04T15:15:10Z
Modified
2026-04-21T04:32:25.252642Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
CVE-2020-24659 affecting package gnutls for versions less than 3.6.14-5
Details

An issue was discovered in GnuTLS before 3.6.15. A server can trigger a NULL pointer dereference in a TLS 1.3 client if a norenegotiation alert is sent with unexpected timing, and then an invalid second handshake occurs. The crash happens in the application's error handling path, where the gnutlsdeinit function is called after detecting a handshake failure.

References

Affected packages

Azure Linux:2 / gnutls

Package

Name
gnutls
Purl
pkg:rpm/azure-linux/gnutls

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.6.14-5

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-6445.json"