CVE-2021-20325: Buffer Overflow

Published Oct 26, 2021
·
Updated

Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regression compared to the versions shipped in Red Hat Enterprise Linux 8.4. A user who installs or updates to Red Hat Enterprise Linux 8.5.0 would be vulnerable to the mentioned CVEs, even if they were properly fixed in Red Hat Enterprise Linux 8.4. CVE-2021-20325 was assigned to that Red Hat specific security regression and it does not affect the upstream versions of httpd.

Other sources

The httpd flaws CVE-2021-40438 (bug 2005117) and CVE-2021-26691 (bug 1966732) were addressed in Red Hat Enterprise Linux 8 via erratum RHSA-2021:3816 released on Oct 12, 2021:

https://access.redhat.com/errata/RHSA-2021:3816

However, those fixes were not included in the httpd update released as part of Red Hat Enterprise Linux 8.5, causing a security regression of previously released fixes. A new CVE id CVE-2021-20325 was assigned for this security regression.

Note that this issue and CVE id is specific to the httpd packages as shipped with Red Hat Enterprise Linux 8 and is not applicable to any upstream httpd version as released by Apache Software Foundation or httpd packages of any other vendor that are not directly based on Red Hat Enterprise Linux 8 packages.

For more information about the original flaws, refer to the specific flaw bugs linked above.

Red Hat

Affected Software

2 affected componentsFixes available
redhat/httpd<2.4.47
2.4.47
redhat Enterprise Linux=8.5.0

Event History

Oct 26, 2021
Data Sourced
via Red Hat·09:57 AM
DescriptionSeverityAffected Software
Feb 18, 2022
CVE Published
via MITRE·05:50 PM
Data Sourced
via MITRE·05:50 PM
DescriptionWeakness

Frequently Asked Questions

1

What is the severity of CVE-2021-20325?

CVE-2021-20325 is considered a medium severity vulnerability due to potential exploitation resulting in security regressions.

2

How do I fix CVE-2021-20325?

To fix CVE-2021-20325, update your Red Hat Enterprise Linux to version 8.5.1 or later.

3

What software is affected by CVE-2021-20325?

CVE-2021-20325 affects the httpd package shipped with Red Hat Enterprise Linux 8.5.0.

4

Is CVE-2021-20325 related to other vulnerabilities?

Yes, CVE-2021-20325 represents missing fixes for CVE-2021-40438 and CVE-2021-26691.

5

What versions of httpd are impacted by CVE-2021-20325?

Versions of httpd up to 2.4.47 are impacted by CVE-2021-20325.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203