CVE-2021-34798: NULL pointer dereference in httpd core
A NULL pointer dereference in httpd allows an unauthenticated remote attacker to crash httpd by providing malformed HTTP requests. The highest threat from this vulnerability is to system availability.
Other sources
Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.
Affected Software
Remediation
Patch Available
Patch Available
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-34798?
CVE-2021-34798 is a vulnerability that allows an unauthenticated remote attacker to crash Apache httpd by providing malformed HTTP requests.
How does CVE-2021-34798 affect system availability?
CVE-2021-34798 poses a high threat to system availability.
What software is affected by CVE-2021-34798?
Apache httpd versions up to and excluding 2.4.49, as well as certain versions of Red Hat httpd and related packages, are affected by CVE-2021-34798.
How do I fix CVE-2021-34798?
To fix CVE-2021-34798, upgrade Apache httpd to version 2.4.49 or apply the appropriate patch from Red Hat.
Where can I find more information about CVE-2021-34798?
You can find more information about CVE-2021-34798 on the Apache httpd website, Red Hat Bugzilla, and Red Hat support policy page.