{
  "document": {
    "aggregate_severity": {
      "text": "High"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/centos6els/vex/2020/cve-2020-24659-els_os-centos6els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-15T08:59:08Z",
      "generator": {
        "date": "2026-09-15T08:59:08Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2020-24659-ELS_OS-CENTOS6ELS",
      "initial_release_date": "2020-09-04T15:15:00Z",
      "revision_history": [
        {
          "date": "2020-09-04T15:15:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-09-15T08:59:08Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2020-24659"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 6",
                "product": {
                  "name": "Community Enterprise Operating System 6",
                  "product_id": "CentOS-6",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:6:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.i686",
                "product": {
                  "name": "gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.i686",
                  "product_id": "gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/gnutls-devel@2.12.23-22.el6.tuxcare.els1?arch=i686"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.i686",
                "product": {
                  "name": "gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.i686",
                  "product_id": "gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/gnutls-guile@2.12.23-22.el6.tuxcare.els1?arch=i686"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "gnutls-0:2.12.23-22.el6.tuxcare.els1.i686",
                "product": {
                  "name": "gnutls-0:2.12.23-22.el6.tuxcare.els1.i686",
                  "product_id": "gnutls-0:2.12.23-22.el6.tuxcare.els1.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/gnutls@2.12.23-22.el6.tuxcare.els1?arch=i686"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "i686"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.x86_64",
                "product": {
                  "name": "gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.x86_64",
                  "product_id": "gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/gnutls-devel@2.12.23-22.el6.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.x86_64",
                "product": {
                  "name": "gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.x86_64",
                  "product_id": "gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/gnutls-guile@2.12.23-22.el6.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "gnutls-utils-0:2.12.23-22.el6.tuxcare.els1.x86_64",
                "product": {
                  "name": "gnutls-utils-0:2.12.23-22.el6.tuxcare.els1.x86_64",
                  "product_id": "gnutls-utils-0:2.12.23-22.el6.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/gnutls-utils@2.12.23-22.el6.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "gnutls-0:2.12.23-22.el6.tuxcare.els1.x86_64",
                "product": {
                  "name": "gnutls-0:2.12.23-22.el6.tuxcare.els1.x86_64",
                  "product_id": "gnutls-0:2.12.23-22.el6.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/gnutls@2.12.23-22.el6.tuxcare.els1?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "CloudLinux"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.i686 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.i686"
        },
        "product_reference": "gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.i686",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.x86_64"
        },
        "product_reference": "gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.x86_64"
        },
        "product_reference": "gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.i686 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.i686"
        },
        "product_reference": "gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.i686",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gnutls-utils-0:2.12.23-22.el6.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:gnutls-utils-0:2.12.23-22.el6.tuxcare.els1.x86_64"
        },
        "product_reference": "gnutls-utils-0:2.12.23-22.el6.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gnutls-0:2.12.23-22.el6.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:gnutls-0:2.12.23-22.el6.tuxcare.els1.x86_64"
        },
        "product_reference": "gnutls-0:2.12.23-22.el6.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gnutls-0:2.12.23-22.el6.tuxcare.els1.i686 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:gnutls-0:2.12.23-22.el6.tuxcare.els1.i686"
        },
        "product_reference": "gnutls-0:2.12.23-22.el6.tuxcare.els1.i686",
        "relates_to_product_reference": "CentOS-6"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2020-24659",
      "cwe": {
        "id": "CWE-476",
        "name": "NULL Pointer Dereference"
      },
      "notes": [
        {
          "category": "description",
          "text": "An issue was discovered in GnuTLS before 3.6.15. A server can trigger a NULL pointer dereference in a TLS 1.3 client if a no_renegotiation alert is sent with unexpected timing, and then an invalid second handshake occurs. The crash happens in the application's error handling path, where the gnutls_deinit function is called after detecting a handshake failure.",
          "title": "Vulnerability description"
        },
        {
          "category": "other",
          "text": "TuxCare has assessed that this vulnerability does not impact any currently supported TuxCare products. This evaluation may change as new information becomes available. For additional details regarding this vulnerability and affected products, refer to the provided references.",
          "title": "Statement"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "CentOS-6:gnutls-0:2.12.23-22.el6.tuxcare.els1.i686",
          "CentOS-6:gnutls-0:2.12.23-22.el6.tuxcare.els1.x86_64",
          "CentOS-6:gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.i686",
          "CentOS-6:gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.x86_64",
          "CentOS-6:gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.i686",
          "CentOS-6:gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.x86_64",
          "CentOS-6:gnutls-utils-0:2.12.23-22.el6.tuxcare.els1.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2020-24659"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00054.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00054.html"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00060.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00060.html"
        },
        {
          "category": "external",
          "summary": "https://gitlab.com/gnutls/gnutls/-/issues/1071",
          "url": "https://gitlab.com/gnutls/gnutls/-/issues/1071"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/62BUAI4FQQLG6VTKRT7SUZPGJJ4NASQ3/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/62BUAI4FQQLG6VTKRT7SUZPGJJ4NASQ3/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AWN56FDLQQXT2D2YHNI4TYH432TDMQ7N/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AWN56FDLQQXT2D2YHNI4TYH432TDMQ7N/"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202009-01",
          "url": "https://security.gentoo.org/glsa/202009-01"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20200911-0006/",
          "url": "https://security.netapp.com/advisory/ntap-20200911-0006/"
        },
        {
          "category": "external",
          "summary": "https://usn.ubuntu.com/4491-1/",
          "url": "https://usn.ubuntu.com/4491-1/"
        },
        {
          "category": "external",
          "summary": "https://www.gnutls.org/security-new.html#GNUTLS-SA-2020-09-04",
          "url": "https://www.gnutls.org/security-new.html#GNUTLS-SA-2020-09-04"
        }
      ],
      "release_date": "2020-09-04T15:15:00Z",
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        },
        {
          "category": "impact",
          "date": "2026-07-09T12:06:11.072153Z",
          "details": "Not affected: CVE-2020-24659 is limited to GnuTLS’s TLS 1.3 client path, a capability introduced only in the 3.6.x series and fixed in 3.6.15. The version in scope (GnuTLS 2.12.23) predates TLS 1.3 and lacks the corresponding handshake/error‑handling code, so the vulnerable path is not present or reachable. This aligns with vendor guidance that marks pre‑3.6 releases as not affected.",
          "product_ids": [
            "CentOS-6:gnutls-0:2.12.23-22.el6.tuxcare.els1.i686",
            "CentOS-6:gnutls-0:2.12.23-22.el6.tuxcare.els1.x86_64",
            "CentOS-6:gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.i686",
            "CentOS-6:gnutls-devel-0:2.12.23-22.el6.tuxcare.els1.x86_64",
            "CentOS-6:gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.i686",
            "CentOS-6:gnutls-guile-0:2.12.23-22.el6.tuxcare.els1.x86_64",
            "CentOS-6:gnutls-utils-0:2.12.23-22.el6.tuxcare.els1.x86_64"
          ]
        }
      ]
    }
  ]
}