GnuTLS version 3.5.12 and earlier is vulnerable to a NULL pointer dereference while decoding a status response TLS extension with valid contents. This could lead to a crash of the GnuTLS server application.
https://www.gnutls.org/security.html#GNUTLS-SA-2017-4
https://access.redhat.com/errata/RHSA-2017:2292