CVE-2021-41524: null pointer dereference in h2 fuzzing
While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.51-28.el8 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.51-28.el7 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.50
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-41524?
CVE-2021-41524 is a null pointer dereference vulnerability in the 2.4.49 version of httpd.
What is the severity of CVE-2021-41524?
CVE-2021-41524 has a severity rating of 7.5 (High).
How does CVE-2021-41524 affect the server?
CVE-2021-41524 allows an external source to cause a Denial of Service (DoS) on the server by sending a specially crafted request.
Which versions of httpd are affected by CVE-2021-41524?
CVE-2021-41524 affects version 2.4.49 of httpd.
How can I fix CVE-2021-41524?
To fix CVE-2021-41524, you should update httpd to version 2.4.50 or higher.