Bug 2017321 (CVE-2021-20325)
Summary: | CVE-2021-20325 httpd: Regression of CVE-2021-40438 and CVE-2021-26691 fixes in Red Hat Enterprise Linux 8.5 | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Riccardo Schirone <rschiron> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | caswilli, csutherl, fjansen, gzaronik, hhorak, jclere, jnakfour, jorton, jwong, jwon, kaycoth, krathod, luhliari, mturk, pjindal, security-response-team, szappis |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | httpd 2.4.47, httpd 2.4.49 | Doc Type: | If docs needed, set a value |
Doc Text: |
Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regression compared to the versions shipped in Red Hat Enterprise Linux 8.4. A user who installs or updates to Red Hat Enterprise Linux 8.5.0 would be vulnerable to the mentioned CVEs, even if they were properly fixed in Red Hat Enterprise Linux 8.4. CVE-2021-20325 was assigned to that Red Hat specific security regression and it does not affect the upstream versions of httpd.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2021-11-10 02:22:53 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2017407, 2017408 | ||
Bug Blocks: | 2017307, 2018438 |
Description
Riccardo Schirone
2021-10-26 09:57:43 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:4537 https://access.redhat.com/errata/RHSA-2021:4537 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-20325 The Red Hat Enterprise Linux 8.5 erratum that introduced this regression is: https://access.redhat.com/errata/RHSA-2021:4257 |