{"id":"CVE-2021-4209","details":"A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances.","modified":"2026-04-02T07:34:44.449301Z","published":"2022-08-24T16:15:09.927Z","related":["MGASA-2022-0098","SUSE-SU-2022:0677-1","SUSE-SU-2022:0678-1","SUSE-SU-2022:0717-1","SUSE-SU-2022:2830-1","openSUSE-SU-2022:0717-1"],"references":[{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20220915-0005/"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2021-4209"},{"type":"ADVISORY","url":"https://gitlab.com/gnutls/gnutls/-/issues/1306"},{"type":"ADVISORY","url":"https://gitlab.com/gnutls/gnutls/-/merge_requests/1503"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2044156"},{"type":"FIX","url":"https://gitlab.com/gnutls/gnutls/-/commit/3db352734472d851318944db13be73da61300568"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/gnutls/gnutls","events":[{"introduced":"0"},{"fixed":"f213ec01faa8fd7e7478f85a76352be875f53e4b"},{"fixed":"3db352734472d851318944db13be73da61300568"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"3.7.3"}]}}],"versions":["3.6.12","3.6.13","3.6.14","3.6.14-windows","3.6.15","3.6.16","3.7.0","3.7.1","3.7.2","gnutls-0-0-7","gnutls-0-1-0-srp","gnutls-0_1_2","gnutls-3_0_12","gnutls0-0-4","gnutls0-0-5","gnutls0-0-6","gnutls_0_1_4","gnutls_0_1_9","gnutls_0_2_0","gnutls_0_2_1","gnutls_0_2_10","gnutls_0_2_11","gnutls_0_2_2","gnutls_0_2_3","gnutls_0_2_4","gnutls_0_2_9","gnutls_0_2_90","gnutls_0_2_91","gnutls_0_3_0","gnutls_0_3_1","gnutls_0_3_2","gnutls_0_3_5","gnutls_0_3_90","gnutls_0_3_91","gnutls_0_3_92","gnutls_0_4_0","gnutls_0_4_1","gnutls_0_4_2","gnutls_0_4_3","gnutls_0_4_with_libtasn1","gnutls_0_5_0","gnutls_0_5_1","gnutls_0_5_10","gnutls_0_5_11","gnutls_0_5_2","gnutls_0_5_3","gnutls_0_5_4","gnutls_0_5_5","gnutls_0_5_6","gnutls_0_5_7","gnutls_0_5_8","gnutls_0_5_9","gnutls_0_5_x_before_export_ciphersuites","gnutls_0_5_x_before_int_fixes","gnutls_0_5_x_before_types_change","gnutls_0_5_x_with_export_ciphersuites","gnutls_0_6_0","gnutls_0_8_0","gnutls_0_8_1","gnutls_0_8_10","gnutls_0_8_11","gnutls_0_8_12","gnutls_0_8_3","gnutls_0_8_4","gnutls_0_8_5","gnutls_0_8_6","gnutls_0_8_7","gnutls_0_8_9","gnutls_0_9_1","gnutls_0_9_2","gnutls_0_9_3","gnutls_0_9_4","gnutls_0_9_5","gnutls_0_9_6","gnutls_0_9_7","gnutls_0_9_8","gnutls_0_9_90","gnutls_0_9_91","gnutls_0_9_92","gnutls_0_9_93","gnutls_0_9_94","gnutls_0_9_95","gnutls_0_9_96","gnutls_0_9_97","gnutls_0_9_98","gnutls_0_9_99","gnutls_1_0_0","gnutls_1_0_1","gnutls_1_0_10","gnutls_1_0_11","gnutls_1_0_12","gnutls_1_0_13","gnutls_1_0_16","gnutls_1_0_17","gnutls_1_0_18","gnutls_1_0_19","gnutls_1_0_2","gnutls_1_0_20","gnutls_1_0_21","gnutls_1_0_22","gnutls_1_0_23","gnutls_1_0_24","gnutls_1_0_25","gnutls_1_0_3","gnutls_1_0_4","gnutls_1_0_5","gnutls_1_0_7","gnutls_1_0_8","gnutls_1_0_9","gnutls_1_1_0","gnutls_1_1_1","gnutls_1_1_10","gnutls_1_1_11","gnutls_1_1_12","gnutls_1_1_13","gnutls_1_1_14","gnutls_1_1_15","gnutls_1_1_16","gnutls_1_1_17","gnutls_1_1_18","gnutls_1_1_19","gnutls_1_1_2","gnutls_1_1_20","gnutls_1_1_21","gnutls_1_1_22","gnutls_1_1_23","gnutls_1_1_3","gnutls_1_1_4","gnutls_1_1_5","gnutls_1_1_6","gnutls_1_1_7","gnutls_1_1_7_pre0","gnutls_1_1_8","gnutls_1_1_9","gnutls_1_2_0","gnutls_1_2_1","gnutls_1_2_10","gnutls_1_2_11","gnutls_1_2_2","gnutls_1_2_3","gnutls_1_2_4","gnutls_1_2_5","gnutls_1_2_6","gnutls_1_2_7","gnutls_1_2_8","gnutls_1_2_9","gnutls_1_3_0","gnutls_1_3_1","gnutls_1_3_2","gnutls_1_3_3","gnutls_1_3_4","gnutls_1_3_5","gnutls_1_4_0","gnutls_1_4_1","gnutls_1_4_2","gnutls_1_4_3","gnutls_1_4_4","gnutls_1_4_5","gnutls_1_5_0","gnutls_1_5_1","gnutls_1_5_2","gnutls_1_5_3","gnutls_1_5_4","gnutls_1_5_5","gnutls_1_6_0","gnutls_1_6_1","gnutls_1_6_2","gnutls_1_6_3","gnutls_1_7_0","gnutls_1_7_1","gnutls_1_7_10","gnutls_1_7_11","gnutls_1_7_12","gnutls_1_7_13","gnutls_1_7_14","gnutls_1_7_15","gnutls_1_7_16","gnutls_1_7_17","gnutls_1_7_18","gnutls_1_7_19","gnutls_1_7_2","gnutls_1_7_3","gnutls_1_7_4","gnutls_1_7_5","gnutls_1_7_6","gnutls_1_7_7","gnutls_1_7_8","gnutls_1_7_8_p11_0","gnutls_1_7_8_p11_1","gnutls_1_7_8_p11_2","gnutls_1_7_9","gnutls_2_0_0","gnutls_2_0_1","gnutls_2_0_2","gnutls_2_0_3","gnutls_2_0_4","gnutls_2_10_0","gnutls_2_10_1","gnutls_2_10_2","gnutls_2_10_3","gnutls_2_10_4","gnutls_2_10_5","gnutls_2_11_3","gnutls_2_11_4","gnutls_2_11_5","gnutls_2_11_6","gnutls_2_11_7","gnutls_2_12_0","gnutls_2_12_1","gnutls_2_12_10","gnutls_2_12_11","gnutls_2_12_12","gnutls_2_12_13","gnutls_2_12_14","gnutls_2_12_14a","gnutls_2_12_15","gnutls_2_12_16","gnutls_2_12_17","gnutls_2_12_18","gnutls_2_12_19","gnutls_2_12_2","gnutls_2_12_20","gnutls_2_12_21","gnutls_2_12_22","gnutls_2_12_23","gnutls_2_12_24","gnutls_2_12_3","gnutls_2_12_4","gnutls_2_12_5","gnutls_2_12_6","gnutls_2_12_6_1","gnutls_2_12_7","gnutls_2_12_7_a","gnutls_2_12_8","gnutls_2_12_9","gnutls_2_1_0","gnutls_2_1_1","gnutls_2_1_2","gnutls_2_1_3","gnutls_2_1_4","gnutls_2_1_5","gnutls_2_1_6","gnutls_2_1_7","gnutls_2_1_8","gnutls_2_2_0","gnutls_2_2_1","gnutls_2_2_2","gnutls_2_2_3","gnutls_2_2_4","gnutls_2_2_5","gnutls_2_3_0","gnutls_2_3_1","gnutls_2_3_10","gnutls_2_3_11","gnutls_2_3_12","gnutls_2_3_13","gnutls_2_3_14","gnutls_2_3_15","gnutls_2_3_2","gnutls_2_3_3","gnutls_2_3_4","gnutls_2_3_4_netconf_0","gnutls_2_3_4_netconf_1","gnutls_2_3_4_netconf_2","gnutls_2_3_5","gnutls_2_3_6","gnutls_2_3_7","gnutls_2_3_8","gnutls_2_3_9","gnutls_2_4_0","gnutls_2_4_1","gnutls_2_4_2","gnutls_2_4_3","gnutls_2_5_0","gnutls_2_5_1","gnutls_2_5_2","gnutls_2_5_3","gnutls_2_5_4","gnutls_2_5_5","gnutls_2_5_6","gnutls_2_5_7","gnutls_2_5_8","gnutls_2_5_9","gnutls_2_6_0","gnutls_2_6_1","gnutls_2_6_2","gnutls_2_6_3","gnutls_2_6_4","gnutls_2_6_5","gnutls_2_6_6","gnutls_2_7_0","gnutls_2_7_1","gnutls_2_7_10","gnutls_2_7_11","gnutls_2_7_12","gnutls_2_7_13","gnutls_2_7_14","gnutls_2_7_2","gnutls_2_7_3","gnutls_2_7_4","gnutls_2_7_5","gnutls_2_7_6","gnutls_2_7_7","gnutls_2_7_8","gnutls_2_7_9","gnutls_2_8_0","gnutls_2_8_1","gnutls_2_8_2","gnutls_2_8_3","gnutls_2_8_4","gnutls_2_8_5","gnutls_2_8_6","gnutls_2_99_0","gnutls_2_99_1","gnutls_2_99_2","gnutls_2_99_3","gnutls_2_99_4","gnutls_2_9_0","gnutls_2_9_1","gnutls_2_9_10","gnutls_2_9_11","gnutls_2_9_12","gnutls_2_9_2","gnutls_2_9_3","gnutls_2_9_4","gnutls_2_9_5","gnutls_2_9_6","gnutls_2_9_7","gnutls_2_9_8","gnutls_2_9_9","gnutls_3_0_0","gnutls_3_0_1","gnutls_3_0_10","gnutls_3_0_11","gnutls_3_0_13","gnutls_3_0_14","gnutls_3_0_15","gnutls_3_0_16","gnutls_3_0_17","gnutls_3_0_18","gnutls_3_0_19","gnutls_3_0_2","gnutls_3_0_20","gnutls_3_0_21","gnutls_3_0_21_real","gnutls_3_0_22","gnutls_3_0_23","gnutls_3_0_24","gnutls_3_0_25","gnutls_3_0_26","gnutls_3_0_27","gnutls_3_0_28","gnutls_3_0_29","gnutls_3_0_3","gnutls_3_0_30","gnutls_3_0_31","gnutls_3_0_32","gnutls_3_0_4","gnutls_3_0_5","gnutls_3_0_6","gnutls_3_0_7","gnutls_3_0_8","gnutls_3_0_9","gnutls_3_1_0","gnutls_3_1_0pre0","gnutls_3_1_1","gnutls_3_1_10","gnutls_3_1_11","gnutls_3_1_12","gnutls_3_1_13","gnutls_3_1_14","gnutls_3_1_15","gnutls_3_1_16","gnutls_3_1_17","gnutls_3_1_18","gnutls_3_1_19","gnutls_3_1_2","gnutls_3_1_20","gnutls_3_1_21","gnutls_3_1_22","gnutls_3_1_23","gnutls_3_1_24","gnutls_3_1_25","gnutls_3_1_26","gnutls_3_1_27","gnutls_3_1_28","gnutls_3_1_3","gnutls_3_1_4","gnutls_3_1_5","gnutls_3_1_6","gnutls_3_1_7","gnutls_3_1_8","gnutls_3_1_9","gnutls_3_2_0","gnutls_3_2_1","gnutls_3_2_10","gnutls_3_2_11","gnutls_3_2_12","gnutls_3_2_12_1","gnutls_3_2_13","gnutls_3_2_14","gnutls_3_2_15","gnutls_3_2_16","gnutls_3_2_17","gnutls_3_2_18","gnutls_3_2_19","gnutls_3_2_2","gnutls_3_2_20","gnutls_3_2_21","gnutls_3_2_3","gnutls_3_2_3pre0","gnutls_3_2_4","gnutls_3_2_5","gnutls_3_2_6","gnutls_3_2_7","gnutls_3_2_8","gnutls_3_2_8_1","gnutls_3_2_9","gnutls_3_3_0","gnutls_3_3_0pre0","gnutls_3_3_1","gnutls_3_3_10","gnutls_3_3_11","gnutls_3_3_12","gnutls_3_3_13","gnutls_3_3_14","gnutls_3_3_15","gnutls_3_3_16","gnutls_3_3_17","gnutls_3_3_18","gnutls_3_3_19","gnutls_3_3_2","gnutls_3_3_20","gnutls_3_3_21","gnutls_3_3_22","gnutls_3_3_23","gnutls_3_3_24","gnutls_3_3_25","gnutls_3_3_26","gnutls_3_3_27","gnutls_3_3_28","gnutls_3_3_29","gnutls_3_3_3","gnutls_3_3_30","gnutls_3_3_4","gnutls_3_3_5","gnutls_3_3_6","gnutls_3_3_7","gnutls_3_3_8","gnutls_3_3_9","gnutls_3_4_0","gnutls_3_4_1","gnutls_3_4_10","gnutls_3_4_11","gnutls_3_4_12","gnutls_3_4_12_win32","gnutls_3_4_13","gnutls_3_4_14","gnutls_3_4_15","gnutls_3_4_16","gnutls_3_4_17","gnutls_3_4_2","gnutls_3_4_3","gnutls_3_4_4","gnutls_3_4_5","gnutls_3_4_6","gnutls_3_4_7","gnutls_3_4_8","gnutls_3_4_9","gnutls_3_5_0","gnutls_3_5_1","gnutls_3_5_10","gnutls_3_5_11","gnutls_3_5_12","gnutls_3_5_13","gnutls_3_5_14","gnutls_3_5_15","gnutls_3_5_16","gnutls_3_5_17","gnutls_3_5_18","gnutls_3_5_19","gnutls_3_5_2","gnutls_3_5_3","gnutls_3_5_4","gnutls_3_5_5","gnutls_3_5_6","gnutls_3_5_7","gnutls_3_5_8","gnutls_3_5_9","gnutls_3_6_0","gnutls_3_6_0_1","gnutls_3_6_1","gnutls_3_6_10","gnutls_3_6_11","gnutls_3_6_11_1","gnutls_3_6_12","gnutls_3_6_2","gnutls_3_6_3","gnutls_3_6_4","gnutls_3_6_5","gnutls_3_6_6","gnutls_3_6_7","gnutls_3_6_8","gnutls_3_6_9"],"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"8.0"}]}],"vanir_signatures":[{"digest":{"length":292,"function_hash":"236935491575988941758897380685262140406"},"target":{"function":"wrap_nettle_hash_fast","file":"lib/nettle/mac.c"},"signature_version":"v1","source":"https://gitlab.com/gnutls/gnutls@3db352734472d851318944db13be73da61300568","deprecated":false,"id":"CVE-2021-4209-1d4b3fe6","signature_type":"Function"},{"digest":{"line_hashes":["275608571458383794299871881526938393840","233275457814939103921727359368080843473","149924555111173732165894474521323559217","34228096393390421288319336369992983832"],"threshold":0.9},"target":{"file":"lib/nettle/mac.c"},"signature_version":"v1","source":"https://gitlab.com/gnutls/gnutls@3db352734472d851318944db13be73da61300568","deprecated":false,"id":"CVE-2021-4209-d7f7968a","signature_type":"Line"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-4209.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}