CVE-2021-20325: Buffer Overflow
Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regression compared to the versions shipped in Red Hat Enterprise Linux 8.4. A user who installs or updates to Red Hat Enterprise Linux 8.5.0 would be vulnerable to the mentioned CVEs, even if they were properly fixed in Red Hat Enterprise Linux 8.4. CVE-2021-20325 was assigned to that Red Hat specific security regression and it does not affect the upstream versions of httpd.
Other sources
The httpd flaws CVE-2021-40438 (bug 2005117) and CVE-2021-26691 (bug 1966732) were addressed in Red Hat Enterprise Linux 8 via erratum RHSA-2021:3816 released on Oct 12, 2021:
https://access.redhat.com/errata/RHSA-2021:3816
However, those fixes were not included in the httpd update released as part of Red Hat Enterprise Linux 8.5, causing a security regression of previously released fixes. A new CVE id CVE-2021-20325 was assigned for this security regression.
Note that this issue and CVE id is specific to the httpd packages as shipped with Red Hat Enterprise Linux 8 and is not applicable to any upstream httpd version as released by Apache Software Foundation or httpd packages of any other vendor that are not directly based on Red Hat Enterprise Linux 8 packages.
For more information about the original flaws, refer to the specific flaw bugs linked above.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-20325?
CVE-2021-20325 is considered a medium severity vulnerability due to potential exploitation resulting in security regressions.
How do I fix CVE-2021-20325?
To fix CVE-2021-20325, update your Red Hat Enterprise Linux to version 8.5.1 or later.
What software is affected by CVE-2021-20325?
CVE-2021-20325 affects the httpd package shipped with Red Hat Enterprise Linux 8.5.0.
Is CVE-2021-20325 related to other vulnerabilities?
Yes, CVE-2021-20325 represents missing fixes for CVE-2021-40438 and CVE-2021-26691.
What versions of httpd are impacted by CVE-2021-20325?
Versions of httpd up to 2.4.47 are impacted by CVE-2021-20325.