It was discovered in gnutls upstream that there is an uninitialized pointer access in gnutls versions 3.6.4 or later which can be triggered by certain post-handshake messages. Upstream issue: https://gitlab.com/gnutls/gnutls/issues/704
Created gnutls tracking bugs for this issue: Affects: fedora-all [bug 1693214]
the tlsfuzzer[1] test-tls13-keyupdate.py[2] test script can be used in concert with valgrind to verify the fix 1 - https://github.com/tomato42/tlsfuzzer 2 - https://github.com/tomato42/tlsfuzzer/pull/501
Hello! according: https://www.gnutls.org/security-new.html#GNUTLS-SA-2019-03-27 it seems that versions since 3.6.4 are affected (not 3.6.3 as originally pointed out by Pedro in the 1st comment). Is also 3.6.3 affected? Thanks!
(In reply to Leonardo Taccari from comment #5) > Hello! > according: > > https://www.gnutls.org/security-new.html#GNUTLS-SA-2019-03-27 > > it seems that versions since 3.6.4 are affected (not 3.6.3 as originally > pointed out by Pedro in the 1st comment). > Is also 3.6.3 affected? > > > Thanks! Yes, I believe you are right. Fixed. Thank you for pointing that out.
Acknowledgments: Name: Hubert Kario (Red Hat QE BaseOS Security team)
External References: https://www.gnutls.org/security-new.html#GNUTLS-SA-2019-03-27
Upstream commit: https://gitlab.com/gnutls/gnutls/commit/96e07075e8f105b13e76b11e493d5aa2dd937226
(In reply to Huzaifa S. Sidhpurwala from comment #7) > Acknowledgments: > > Name: Hubert Kario (Red Hat QE BaseOS Security team) Actually the issue was identified by Daiki Ueno (Red Hat BaseOS Crypto team), I've just slightly extended tests originally written by Róbert Kolcún.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2019:3600 https://access.redhat.com/errata/RHSA-2019:3600
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-3836