CVE-2021-3449

high
Published 2021-05-01 · Modified 2024-12-16
CVSS v3
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v2
VIR risk
8.0

Description

An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2021-3449

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2021:1024

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2021-3449.html

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-202103-10

OS impact

OSVersionStatusFixed in
arch archfixed1.1.1.k-1
suse slesaffected
rockylinux rocky8fixed
debian debianbookwormfixed1.1.1k-1
debian debianbullseyefixed1.1.1k-1
debian debianforkyfixed1.1.1k-1
debian debiansidfixed1.1.1k-1
debian debiantrixiefixed1.1.1k-1

Package impact

EcosystemPackageVulnerableFixed
rust crates.ioopenssl-src
rust crates.ioopenssl-src<111.15.0111.15.0
rust crates.ioopenssl-src>=0.0.0-0,<111.15.0111.15.0

References

Verify integrity in audit chain (admin only). AS-IS.