CVE-2020-24659: Null Pointer Dereference
An issue was discovered in GnuTLS before 3.6.15. A server can trigger a NULL pointer dereference in a TLS 1.3 client if a norenegotiation alert is sent with unexpected timing, and then an invalid second handshake occurs. The crash happens in the application's error handling path, where the gnutlsdeinit function is called after detecting a handshake failure.
Other sources
GnuTLS is vulnerable to a denial of service, caused by a NULL pointer dereference. By sending specially-crafted messages, a remote attacker could exploit this vulnerability to cause the application to crash.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-24659?
CVE-2020-24659 is a vulnerability in GnuTLS that can be exploited to cause a denial of service.
How severe is CVE-2020-24659?
CVE-2020-24659 has a severity rating of 7.5 (high).
What is the affected software for CVE-2020-24659?
The affected software for CVE-2020-24659 includes GnuTLS versions up to and including 3.6.15, Ubuntu gnutls28 version 3.6.13-2ubuntu1.3, Fedora 32 and 33, openSUSE Leap 15.1 and 15.2, and Canonical Ubuntu Linux 20.04 LTS.
How do I fix CVE-2020-24659?
To fix CVE-2020-24659, update GnuTLS to version 3.6.15-1 or later.
Where can I find more information about CVE-2020-24659?
You can find more information about CVE-2020-24659 at the following references: [1], [2], [3].