CVE-2021-20232 is a critical use-after-free vulnerability in the gnutls library, specifically within the client_send_params function in lib/ext/pre_shared_key.c. This flaw affects various versions of Fedora, Red Hat Enterprise Linux, and gnutls itself. With a CVSS score of 9.8 (Critical), this vulnerability is remotely exploitable with low attack complexity and no user interaction required, potentially leading to complete compromise of confidentiality, integrity, and availability. The underlying issue is a CWE-416 (Use-After-Free). Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. The vulnerability has received minimal community discussion and media coverage, indicating a low level of public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.6.3, < 3.7.1CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
ctrlX Multiple Vulnerabilities
Apr 23, 2021ctrlX Multiple Vulnerabilities
Apr 23, 2021ctrlX Multiple Vulnerabilities
Apr 23, 2021ctrlX Multiple Vulnerabilities
Apr 23, 2021ctrlX Multiple Vulnerabilities
Apr 23, 2021ctrlX Multiple Vulnerabilities
Apr 23, 2021gnutls: Use after free in client_send_params in lib/ext/pre_shared_key.c
Mar 12, 2021A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potential consequences.
Mar 9, 2021