Vulnerability record · CVE-2021-3712 · published 24 August 2021
CVE-2021-3712: OpenSSL ASN.1 string printing out-of-bounds read
OOpenssl · Openssl
OpenSSL functions that print ASN.1 data assume ASN1_STRING buffers are NUL terminated, but applications can construct valid ASN1_STRING structures without NUL termination via direct data/length assignment or ASN1_STRING_set0(). When such a string is printed or processed (including name constraints, X509_get1_email, X509_REQ_get1_email, X509_get1_ocsp), a read buffer overrun occurs. It matters because the overrun can crash the process or leak private memory such as keys or plaintext.
Description
ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a strict requirement, ASN.1 strings that are parsed using OpenSSL's own "d2i" functions (and other similar parsing functions) as well as any string whose value has been set with the ASN1_STRING_set() function will additionally NUL terminate the byte array in the ASN1_STRING structure. However, it is possible for applications to directly construct valid ASN1_STRING structures which do not NUL terminate the byte array by directly setting the "data" and "length" fields in the ASN1_STRING array. This can also happen by using the ASN1_STRING_set0() function. Numerous OpenSSL functions that print ASN.1 data have been found to assume that the ASN1_STRING byte array will be NUL terminated, even though this is not guaranteed for strings that have been directly constructed. Where an application requests an ASN.1 structure to be printed, and where that ASN.1 structure contains ASN1_STRINGs that have been directly constructed by the application without NUL terminating the "data" field, then a read buffer overrun can occur. The same thing can also occur during name constraints processing of certificates (for example if a certificate has been directly constructed by the application instead of loading it via the OpenSSL parsing functions, and the certificate contains non NUL terminated ASN1_STRING structures). It can also occur in the X509_get1_email(), X509_REQ_get1_email() and X509_get1_ocsp() functions. If a malicious actor can cause an application to directly construct an ASN1_STRING and then process it through one of the affected OpenSSL functions then this issue could be hit. This might result in a crash (causing a Denial of Service attack). It could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext). Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k). Fixed in OpenSSL 1.0.2za (Affected 1.0.2-1.0.2y).
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
Automated analysis
high priorityCVSS 7.4 high severity with network reachability and high EPSS percentile, though exploitation requires an application that directly constructs ASN1_STRING structures.
What it is
OpenSSL functions that print ASN.1 data assume ASN1_STRING buffers are NUL terminated, but applications can construct valid ASN1_STRING structures without NUL termination via direct data/length assignment or ASN1_STRING_set0(). When such a string is printed or processed (including name constraints, X509_get1_email, X509_REQ_get1_email, X509_get1_ocsp), a read buffer overrun occurs. It matters because the overrun can crash the process or leak private memory such as keys or plaintext.
Impact
An attacker who can get an application to construct and then process a non-NUL-terminated ASN1_STRING can cause a denial of service via crash or read out-of-bounds memory, potentially disclosing private keys or sensitive plaintext.
Attack surface
Reached over the network (AV:N) with no privileges or user interaction required, but exploitation depends on the target application constructing ASN1_STRING structures directly rather than through OpenSSL parsing, which is why the vector rates complexity as high.
Exploitation
Not listed in CISA KEV and no ransomware usage documented; EPSS 30-day probability is about 0.50 (98.9th percentile), and references are advisories and patches rather than public exploit code.
What to do
- Upgrade OpenSSL to 1.1.1l or 1.0.2za (or later) on all affected hosts and embedded products.
- Apply vendor patches for downstream products (Debian, NetApp, McAfee, Oracle, Siemens, Tenable) that bundle OpenSSL.
- Audit application code for direct ASN1_STRING data/length assignment and ASN1_STRING_set0() use, and ensure NUL termination or avoid printing such strings.
- Track remaining exposure through SBOM or inventory of OpenSSL versions in appliances and third-party software.
Detection
- Search application and system logs for crashes or abnormal terminations in processes that print or parse ASN.1/X.509 data.
- Inventory OpenSSL versions across hosts and containers to find builds older than 1.1.1l or 1.0.2za.
- Monitor for unexpected memory disclosure patterns or anomalous certificate/ASN.1 processing errors in TLS and PKI services.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
32 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-3712 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-3712), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.