Bug 1962254 (CVE-2021-28662)

Summary: CVE-2021-28662 squid: denial of service in HTTP response processing
Product: [Other] Security Response Reporter: Mauro Matteo Cascella <mcascell>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: anon.amish, code, icesalov, jonathansteffan, luhliari
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: squid 4.15, squid 5.0.6 Doc Type: If docs needed, set a value
Doc Text:
An input validation flaw was found in Squid. This issue could allow a remote server to perform a denial of service against all clients using the proxy when delivering HTTP response messages. The highest threat from this vulnerability is to system availability.
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-11-09 18:54:14 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1963381, 1963382, 1963383    
Bug Blocks: 1959539    

Description Mauro Matteo Cascella 2021-05-19 15:18:58 UTC
Due to an input validation bug Squid is vulnerable to a Denial of Service against all clients using the proxy. This problem allows a remote server to perform Denial of Service when delivering HTTP Response messages. The issue trigger is a header which can be expected to exist in HTTP traffic without any malicious intent by the server.

Upstream security advisory:
https://github.com/squid-cache/squid/security/advisories/GHSA-jjq6-mh2h-g39h

Comment 1 Mauro Matteo Cascella 2021-05-22 20:26:21 UTC
Created squid tracking bugs for this issue:

Affects: fedora-all [bug 1963381]

Comment 6 Yadnyawalk Tale 2021-10-19 04:49:27 UTC
The supported versions of Red Hat Satellite does not ship Squid and only consumed through Red Hat Enterprise Linux repository. Product uses older version Squid which is not affected by vulnerability.

Comment 7 errata-xmlrpc 2021-11-09 18:05:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2021:4292 https://access.redhat.com/errata/RHSA-2021:4292

Comment 8 Product Security DevOps Team 2021-11-09 18:54:12 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2021-28662