CVE & CISA-KEV Catalog

CVE-2021-3712

HIGHEPSS 99th pctl
7.4
CVSS v3
NVD

Description

ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a strict requirement, ASN.1 strings that are parsed using OpenSSL's own "d2i" functions (and other similar parsing functions) as well as any string whose value has been set with the ASN1_STRING_set() function will additionally NUL terminate the byte array in the ASN1_STRING structure. However, it is possible for applications to directly construct valid ASN1_STRING structures which do not NUL terminate the byte array by directly setting the "data" and "length" fields in the ASN1_STRING array. This can also happen by using the ASN1_STRING_set0() function. Numerous OpenSSL functions that print ASN.1 data have been found to assume that the ASN1_STRING byte array will be NUL terminated, even though this is not guaranteed for strings that have been directly constructed. Where an application requests an ASN.1 structure to be printed, and where that ASN.1 structure contains ASN1_STRINGs that have been directly constructed by the application without NUL terminating the "data" field, then a read buffer overrun can occur. The same thing can also occur during name constraints processing of certificates (for example if a certificate has been directly constructed by the application instead of loading it via the OpenSSL parsing functions, and the certificate contains non NUL terminated ASN1_STRING structures). It can also occur in the X509_get1_email(), X509_REQ_get1_email() and X509_get1_ocsp() functions. If a malicious actor can cause an application to directly construct an ASN1_STRING and then process it through one of the affected OpenSSL functions then this issue could be hit. This might result in a crash (causing a Denial of Service attack). It could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext). Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k). Fixed in OpenSSL 1.0.2za (Affected 1.0.2-1.0.2y).

How to fix

Remediation Available
opensslDebian
Fixed in:1.1.1k-1+deb11u1CVE-2021-3712
Fixed in:1.1.1l-1CVE-2021-3712
Fixed in:1.1.1l-1CVE-2021-3712
Fixed in:1.1.1l-1CVE-2021-3712
edk2Ubuntu
Fixed in:0~20191122.bd85bf54-2ubuntu3.3USN-5088-1
Fixed in:2022.02-3ubuntu0.22.04.4USN-7894-1
Fixed in:2024.02-2ubuntu0.6USN-7894-1
libssl1.0.0Ubuntu
Fixed in:1.0.1f-1ubuntu2.27+esm3USN-5051-2
Fixed in:1.0.2g-1ubuntu4.20+esm1USN-5051-2
Fixed in:1.0.2n-1ubuntu5.7USN-5051-3
libssl1.1Ubuntu
Fixed in:1.1.1-1ubuntu2.1~18.04.13USN-5051-1
Fixed in:1.1.1f-1ubuntu2.8USN-5051-1
opensslUbuntu
Fixed in:1.0.1f-1ubuntu2.27+esm3USN-5051-2
Fixed in:1.0.2g-1ubuntu4.20+esm1USN-5051-2
Fixed in:1.1.1-1ubuntu2.1~18.04.13USN-5051-1
Fixed in:1.1.1f-1ubuntu2.8USN-5051-1
openssl1.0Ubuntu
Fixed in:1.0.2n-1ubuntu5.7USN-5051-3
ovmfUbuntu
Fixed in:0~20191122.bd85bf54-2ubuntu3.3USN-5088-1
Fixed in:2022.02-3ubuntu0.22.04.4USN-7894-1
Fixed in:2024.02-2ubuntu0.6USN-7894-1
ovmf-ia32Ubuntu
Fixed in:2022.02-3ubuntu0.22.04.4USN-7894-1
Fixed in:2024.02-2ubuntu0.6USN-7894-1
qemu-efiUbuntu
Fixed in:0~20191122.bd85bf54-2ubuntu3.3USN-5088-1
Fixed in:2022.02-3ubuntu0.22.04.4USN-7894-1
qemu-efi-aarch64Ubuntu
Fixed in:0~20191122.bd85bf54-2ubuntu3.3USN-5088-1
Fixed in:2022.02-3ubuntu0.22.04.4USN-7894-1
Fixed in:2024.02-2ubuntu0.6USN-7894-1
qemu-efi-armUbuntu
Fixed in:0~20191122.bd85bf54-2ubuntu3.3USN-5088-1
Fixed in:2022.02-3ubuntu0.22.04.4USN-7894-1
Fixed in:2024.02-2ubuntu0.6USN-7894-1
qemu-efi-riscv64Ubuntu
Fixed in:2024.02-2ubuntu0.6USN-7894-1

TridentStack Control can deploy fixes like this automatically across your Windows, macOS, and Linux fleet. See how it works

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredNone
User InteractionNone
ScopeUnchanged

Impact

ConfidentialityHigh
IntegrityNone
AvailabilityHigh

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H

Exploit Intelligence

50.44%probability of exploitation in 30 days
99thpercentile

Very high risk: more likely to be exploited than 99% of all known CVEs.

References

Related Vulnerabilities

Other CWE-125 (Out-of-bounds Read) vulnerabilities, ordered by exploit likelihood. View all

CVESeverityCVSSEPSSExploitedFix
CVE-2014-0160High7.5100%KEVFix
CVE-2025-5777High7.5100%KEV + RansomFix
CVE-2021-4034High7.895%KEVFix
CVE-2023-21769High7.592%-Fix
CVE-2020-8794Critical9.889%-Fix
CVE-2023-49285High8.689%-Fix
Embed a live status badge for CVE-2021-3712
CVE-2021-3712 severity badge

Markdown

[![CVE-2021-3712](https://tridentstack.com/cve/badge/CVE-2021-3712.svg)](https://tridentstack.com/cve/CVE-2021-3712)

HTML

<a href="https://tridentstack.com/cve/CVE-2021-3712"><img src="https://tridentstack.com/cve/badge/CVE-2021-3712.svg" alt="CVE-2021-3712"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

See how it worksStart freeThis CVE lookup is free and always will be.

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2026-04-16.