{"id":"UBUNTU-CVE-2021-4209","details":"A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances.","modified":"2026-07-22T11:34:31.378979112Z","published":"2022-02-22T20:07:00Z","related":["USN-5550-1","USN-5750-1"],"upstream":["CVE-2021-4209"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-4209"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2021-4209"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-5550-1"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-5750-1"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2021-4209"}],"affected":[{"package":{"name":"gnutls26","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/gnutls26?arch=source&distro=esm-infra-legacy%2Ftrusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.12.23-1ubuntu4","2.12.23-1ubuntu5","2.12.23-12ubuntu1","2.12.23-12ubuntu2","2.12.23-12ubuntu2.1","2.12.23-12ubuntu2.2","2.12.23-12ubuntu2.3","2.12.23-12ubuntu2.4","2.12.23-12ubuntu2.5","2.12.23-12ubuntu2.6","2.12.23-12ubuntu2.7","2.12.23-12ubuntu2.8","2.12.23-12ubuntu2.10+esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"gnutls-bin","binary_version":"3.0.11+really2.12.23-12ubuntu2.10+esm1"},{"binary_name":"libgnutls-openssl27","binary_version":"2.12.23-12ubuntu2.10+esm1"},{"binary_name":"libgnutls26","binary_version":"2.12.23-12ubuntu2.10+esm1"},{"binary_version":"2.12.23-12ubuntu2.10+esm1","binary_name":"libgnutlsxx27"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-4209.json"}},{"package":{"name":"gnutls28","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/gnutls28?arch=source&distro=esm-infra%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.4.10-4ubuntu1.9+esm1"}]}],"versions":["3.3.15-5ubuntu2","3.3.18-1ubuntu1","3.3.20-1ubuntu1","3.4.9-2ubuntu1","3.4.10-4ubuntu1","3.4.10-4ubuntu1.1","3.4.10-4ubuntu1.2","3.4.10-4ubuntu1.3","3.4.10-4ubuntu1.4","3.4.10-4ubuntu1.5","3.4.10-4ubuntu1.6","3.4.10-4ubuntu1.7","3.4.10-4ubuntu1.8","3.4.10-4ubuntu1.9"],"ecosystem_specific":{"binaries":[{"binary_name":"gnutls-bin","binary_version":"3.4.10-4ubuntu1.9+esm1"},{"binary_version":"3.4.10-4ubuntu1.9+esm1","binary_name":"guile-gnutls"},{"binary_name":"libgnutls-openssl27","binary_version":"3.4.10-4ubuntu1.9+esm1"},{"binary_name":"libgnutls30","binary_version":"3.4.10-4ubuntu1.9+esm1"},{"binary_name":"libgnutlsxx28","binary_version":"3.4.10-4ubuntu1.9+esm1"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-4209.json"}},{"package":{"name":"gnutls28","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/gnutls28?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.5.18-1ubuntu1.6"}]}],"versions":["3.5.8-6ubuntu3","3.5.17-1ubuntu1","3.5.17-1ubuntu3","3.5.18-1ubuntu1","3.5.18-1ubuntu1.1","3.5.18-1ubuntu1.2","3.5.18-1ubuntu1.3","3.5.18-1ubuntu1.4","3.5.18-1ubuntu1.5"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"3.5.18-1ubuntu1.6","binary_name":"gnutls-bin"},{"binary_name":"libgnutls-dane0","binary_version":"3.5.18-1ubuntu1.6"},{"binary_name":"libgnutls-openssl27","binary_version":"3.5.18-1ubuntu1.6"},{"binary_name":"libgnutls30","binary_version":"3.5.18-1ubuntu1.6"},{"binary_name":"libgnutlsxx28","binary_version":"3.5.18-1ubuntu1.6"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-4209.json"}},{"package":{"name":"gnutls28","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/gnutls28?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.13-2ubuntu1.7"}]}],"versions":["3.6.9-5ubuntu1","3.6.9-5ubuntu2","3.6.10-5","3.6.11.1-2","3.6.11.1-2ubuntu2","3.6.13-2ubuntu1","3.6.13-2ubuntu1.1","3.6.13-2ubuntu1.2","3.6.13-2ubuntu1.3","3.6.13-2ubuntu1.6"],"ecosystem_specific":{"binaries":[{"binary_name":"gnutls-bin","binary_version":"3.6.13-2ubuntu1.7"},{"binary_version":"3.6.13-2ubuntu1.7","binary_name":"guile-gnutls"},{"binary_version":"3.6.13-2ubuntu1.7","binary_name":"libgnutls-dane0"},{"binary_name":"libgnutls-openssl27","binary_version":"3.6.13-2ubuntu1.7"},{"binary_name":"libgnutls30","binary_version":"3.6.13-2ubuntu1.7"},{"binary_name":"libgnutlsxx28","binary_version":"3.6.13-2ubuntu1.7"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-4209.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"low"}]}