CVE-2021-26690: mod_session NULL pointer dereference
A NULL pointer dereference was found in Apache httpd modsession. The highest threat from this vulnerability is to system availability.
Other sources
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by modsession can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service
In Apache httpd before 2.4.48 modsession has a NULL pointer dereference in parser.
References:
https://github.com/apache/httpd/commit/67bd9bfe6c38831e14fe7122f1d84391472498f8
— Red Hat
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-26690?
CVE-2021-26690 is a vulnerability in Apache httpd mod_session that can cause a NULL pointer dereference and crash, leading to a possible Denial of Service (DoS).
Which versions of Apache HTTP Server are affected by CVE-2021-26690?
Apache HTTP Server versions 2.4.0 to 2.4.46 are affected by CVE-2021-26690.
What is the severity of CVE-2021-26690?
The severity of CVE-2021-26690 is high, with a CVSS score of 7.5.
How can CVE-2021-26690 be fixed?
To fix CVE-2021-26690, upgrade to Apache HTTP Server version 2.4.47 or higher.
Are there any references for CVE-2021-26690?
Yes, you can find references for CVE-2021-26690 at the following links: [GitHub Commit](https://github.com/apache/httpd/commit/67bd9bfe6c38831e14fe7122f1d84391472498f8), [Red Hat Support](https://access.redhat.com/support/policy/updates/jboss_notes), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1968308).