{"id":"UBUNTU-CVE-2021-3449","details":"An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).","modified":"2026-05-22T22:15:06.081223978Z","published":"2021-03-25T00:00:00Z","related":["USN-4891-1","USN-5038-1"],"upstream":["CVE-2021-3449"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-3449"},{"type":"REPORT","url":"https://www.openssl.org/news/secadv/20210325.txt"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-4891-1"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-5038-1"},{"type":"REPORT","url":"https://github.com/nodejs/node/pull/38083"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2021-3449"}],"affected":[{"package":{"name":"openssl","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/openssl?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.1-1ubuntu2.1~18.04.9"}]}],"versions":["1.0.2g-1ubuntu13","1.0.2g-1ubuntu14","1.0.2n-1ubuntu1","1.1.0g-2ubuntu1","1.1.0g-2ubuntu2","1.1.0g-2ubuntu3","1.1.0g-2ubuntu4","1.1.0g-2ubuntu4.1","1.1.0g-2ubuntu4.3","1.1.1-1ubuntu2.1~18.04.1","1.1.1-1ubuntu2.1~18.04.2","1.1.1-1ubuntu2.1~18.04.3","1.1.1-1ubuntu2.1~18.04.4","1.1.1-1ubuntu2.1~18.04.5","1.1.1-1ubuntu2.1~18.04.6","1.1.1-1ubuntu2.1~18.04.7","1.1.1-1ubuntu2.1~18.04.8"],"ecosystem_specific":{"binaries":[{"binary_version":"1.1.1-1ubuntu2.1~18.04.9","binary_name":"libssl1.1"},{"binary_name":"openssl","binary_version":"1.1.1-1ubuntu2.1~18.04.9"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3449.json"}},{"package":{"name":"postgresql-10","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/postgresql-10?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.18-0ubuntu0.18.04.1"}]}],"versions":["10.1-1","10.1-2","10.2-1","10.3-1","10.4-0ubuntu0.18.04","10.5-0ubuntu0.18.04","10.6-0ubuntu0.18.04.1","10.7-0ubuntu0.18.04.1","10.8-0ubuntu0.18.04.1","10.9-0ubuntu0.18.04.1","10.10-0ubuntu0.18.04.1","10.12-0ubuntu0.18.04.1","10.14-0ubuntu0.18.04.1","10.15-0ubuntu0.18.04.1","10.16-0ubuntu0.18.04.1","10.17-0ubuntu0.18.04.1"],"ecosystem_specific":{"binaries":[{"binary_name":"libecpg-compat3","binary_version":"10.18-0ubuntu0.18.04.1"},{"binary_name":"libecpg6","binary_version":"10.18-0ubuntu0.18.04.1"},{"binary_version":"10.18-0ubuntu0.18.04.1","binary_name":"libpgtypes3"},{"binary_name":"libpq5","binary_version":"10.18-0ubuntu0.18.04.1"},{"binary_name":"postgresql-10","binary_version":"10.18-0ubuntu0.18.04.1"},{"binary_version":"10.18-0ubuntu0.18.04.1","binary_name":"postgresql-client-10"},{"binary_version":"10.18-0ubuntu0.18.04.1","binary_name":"postgresql-doc-10"},{"binary_name":"postgresql-plperl-10","binary_version":"10.18-0ubuntu0.18.04.1"},{"binary_version":"10.18-0ubuntu0.18.04.1","binary_name":"postgresql-plpython-10"},{"binary_name":"postgresql-plpython3-10","binary_version":"10.18-0ubuntu0.18.04.1"},{"binary_version":"10.18-0ubuntu0.18.04.1","binary_name":"postgresql-pltcl-10"},{"binary_name":"postgresql-server-dev-10","binary_version":"10.18-0ubuntu0.18.04.1"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3449.json"}},{"package":{"name":"openssl","ecosystem":"Ubuntu:Pro:FIPS-updates:18.04:LTS","purl":"pkg:deb/ubuntu/openssl?arch=source&distro=fips-updates%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.1-1ubuntu2.fips.2.1~18.04.9.1"}]}],"versions":["1.1.1-1ubuntu2.fips.2.1~18.04.5.1","1.1.1-1ubuntu2.fips.2.1~18.04.6.1","1.1.1-1ubuntu2.fips.2.1~18.04.7.1"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_version":"1.1.1-1ubuntu2.fips.2.1~18.04.9.1","binary_name":"libssl1.1"},{"binary_name":"libssl1.1-hmac","binary_version":"1.1.1-1ubuntu2.fips.2.1~18.04.9.1"},{"binary_name":"openssl","binary_version":"1.1.1-1ubuntu2.fips.2.1~18.04.9.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3449.json"}},{"package":{"name":"openssl","ecosystem":"Ubuntu:Pro:FIPS:18.04:LTS","purl":"pkg:deb/ubuntu/openssl?arch=source&distro=fips%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.1.1-1ubuntu2.fips.2.1~18.04.3.1","1.1.1-1ubuntu2.fips.2.1~18.04.15.2"],"ecosystem_specific":{"binaries":[{"binary_name":"libssl1.1","binary_version":"1.1.1-1ubuntu2.fips.2.1~18.04.15.2"},{"binary_name":"libssl1.1-hmac","binary_version":"1.1.1-1ubuntu2.fips.2.1~18.04.15.2"},{"binary_name":"openssl","binary_version":"1.1.1-1ubuntu2.fips.2.1~18.04.15.2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3449.json"}},{"package":{"name":"openssl","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/openssl?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.1f-1ubuntu2.3"}]}],"versions":["1.1.1c-1ubuntu4","1.1.1d-2ubuntu3","1.1.1d-2ubuntu6","1.1.1f-1ubuntu1","1.1.1f-1ubuntu2","1.1.1f-1ubuntu2.1","1.1.1f-1ubuntu2.2"],"ecosystem_specific":{"binaries":[{"binary_version":"1.1.1f-1ubuntu2.3","binary_name":"libssl1.1"},{"binary_name":"openssl","binary_version":"1.1.1f-1ubuntu2.3"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3449.json"}},{"package":{"name":"postgresql-12","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/postgresql-12?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"12.8-0ubuntu0.20.04.1"}]}],"versions":["12.0-1","12.1-1","12.1-2build1","12.2-1","12.2-1ubuntu2","12.2-4","12.4-0ubuntu0.20.04.1","12.5-0ubuntu0.20.04.1","12.6-0ubuntu0.20.04.1","12.7-0ubuntu0.20.04.1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"libecpg-compat3","binary_version":"12.8-0ubuntu0.20.04.1"},{"binary_name":"libecpg6","binary_version":"12.8-0ubuntu0.20.04.1"},{"binary_name":"libpgtypes3","binary_version":"12.8-0ubuntu0.20.04.1"},{"binary_name":"libpq5","binary_version":"12.8-0ubuntu0.20.04.1"},{"binary_name":"postgresql-12","binary_version":"12.8-0ubuntu0.20.04.1"},{"binary_name":"postgresql-client-12","binary_version":"12.8-0ubuntu0.20.04.1"},{"binary_version":"12.8-0ubuntu0.20.04.1","binary_name":"postgresql-doc-12"},{"binary_name":"postgresql-plperl-12","binary_version":"12.8-0ubuntu0.20.04.1"},{"binary_version":"12.8-0ubuntu0.20.04.1","binary_name":"postgresql-plpython3-12"},{"binary_version":"12.8-0ubuntu0.20.04.1","binary_name":"postgresql-pltcl-12"},{"binary_version":"12.8-0ubuntu0.20.04.1","binary_name":"postgresql-server-dev-12"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3449.json"}},{"package":{"name":"openssl","ecosystem":"Ubuntu:Pro:FIPS-updates:20.04:LTS","purl":"pkg:deb/ubuntu/openssl?arch=source&distro=fips-updates%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.1f-1ubuntu2.fips.7"}]}],"ecosystem_specific":{"binaries":[{"binary_name":"libssl1.1","binary_version":"1.1.1f-1ubuntu2.fips.7"},{"binary_version":"1.1.1f-1ubuntu2.fips.7","binary_name":"libssl1.1-hmac"},{"binary_name":"openssl","binary_version":"1.1.1f-1ubuntu2.fips.7"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3449.json"}},{"package":{"name":"openssl","ecosystem":"Ubuntu:Pro:FIPS:20.04:LTS","purl":"pkg:deb/ubuntu/openssl?arch=source&distro=fips%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.1f-1ubuntu2.fips.2.8"}]}],"ecosystem_specific":{"binaries":[{"binary_name":"libssl1.1","binary_version":"1.1.1f-1ubuntu2.fips.2.8"},{"binary_version":"1.1.1f-1ubuntu2.fips.2.8","binary_name":"libssl1.1-hmac"},{"binary_version":"1.1.1f-1ubuntu2.fips.2.8","binary_name":"openssl"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3449.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"high"}]}