CVE-2021-20231: Use After Free
A flaw was found in gnutls. A use after free issue in client sending keyshare extension may lead to memory corruption and other consequences.
Other sources
GnuTLS is vulnerable to a denial of service, caused by a use-after-free issue in client sending keyshare extension. By sending a specially-crafted request, an attacker could exploit this vulnerability to cause memory corruption and other consequences.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-20231?
CVE-2021-20231 is a vulnerability in GnuTLS that allows for a denial of service attack by exploiting a use-after-free issue in client sending key_share extension.
What can an attacker do with CVE-2021-20231?
By exploiting CVE-2021-20231, an attacker can cause memory corruption and other consequences, leading to a denial of service.
Which software is affected by CVE-2021-20231?
IBM QRadar SIEM versions 7.5.0 GA, 7.4.3 GA - 7.4.3 FP4, and 7.3.3 GA - 7.3.3 FP10 are affected by CVE-2021-20231.
How severe is CVE-2021-20231?
CVE-2021-20231 has a severity rating of 7.4, which is considered high.
How can I fix CVE-2021-20231?
To fix CVE-2021-20231, you should apply the relevant patches provided by IBM for the affected versions of QRadar SIEM.