A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potential consequences. References: https://gitlab.com/gnutls/gnutls/-/issues/1151
Created gnutls tracking bugs for this issue: Affects: fedora-all [bug 1938149] Created mingw-gnutls tracking bugs for this issue: Affects: fedora-all [bug 1938150]
External References: https://www.gnutls.org/security-new.html#GNUTLS-SA-2021-03-10
Acknowledgments: Name: GnuTLS project Upstream: Ivan Nikolchev
Upstream commit: https://gitlab.com/gnutls/gnutls/-/commit/75a937d97f4fefc6f9b08e3791f151445f551cb3
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:4451 https://access.redhat.com/errata/RHSA-2021:4451
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-20232