CVE-2021-20231

Source
https://cve.org/CVERecord?id=CVE-2021-20231
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-20231.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-20231
Downstream
ALPINE (1)
AZL (1)
BELL (1)
CGA (2)
DEBIAN (1)
JLSEC (1)
MGASA (1)
OESA (1)
openSUSE (1)
RHSA (1)
RLSA (1)
SUSE (2)
UBUNTU (1)
Related
Published
2021-03-12T19:15:13Z
Modified
2026-08-07T11:48:34Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.

Database specific
{
    "unresolved_ranges":  [
        {
            "cpes":  [
                "cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "introduced":  "34"
                },
                {
                    "last_affected":  "34"
                }
            ],
            "source":  "CPE_STRING",
            "vendor_product":  "fedoraproject:fedora"
        },
        {
            "cpes":  [
                "cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "introduced":  "8.0"
                },
                {
                    "last_affected":  "8.0"
                }
            ],
            "source":  "CPE_STRING",
            "vendor_product":  "redhat:enterprise_linux"
        }
    ]
}
References

Affected packages

Git / github.com/gnutls/gnutls

Affected ranges

Type
GIT
Repo
https://github.com/gnutls/gnutls
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "3.6.3"
        },
        {
            "fixed":  "3.7.1"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

3.*
3.6.12
3.6.13
3.6.14
3.7.0
Other
gnutls_3_6_10
gnutls_3_6_11
gnutls_3_6_11_1
gnutls_3_6_12
gnutls_3_6_3
gnutls_3_6_4
gnutls_3_6_5
gnutls_3_6_6
gnutls_3_6_7
gnutls_3_6_9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-20231.json"

Git / gitlab.com/gnutls/gnutls

Affected ranges

Type
GIT
Repo
https://gitlab.com/gnutls/gnutls
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "3.6.3"
        },
        {
            "fixed":  "3.7.1"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

3.*
3.6.12
3.6.13
3.6.14
3.7.0
Other
gnutls_3_6_10
gnutls_3_6_11
gnutls_3_6_11_1
gnutls_3_6_12
gnutls_3_6_3
gnutls_3_6_4
gnutls_3_6_5
gnutls_3_6_6
gnutls_3_6_7
gnutls_3_6_9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-20231.json"