Bug 2042900 (CVE-2021-4213) - CVE-2021-4213 JSS: memory leak in TLS connection leads to OOM
Summary: CVE-2021-4213 JSS: memory leak in TLS connection leads to OOM
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2021-4213
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
: 2011102 (view as bug list)
Depends On: 2184498 2046022 2046023 2052631 2052632 2142975
Blocks: 2042903
TreeView+ depends on / blocked
 
Reported: 2022-01-20 10:25 UTC by Cedric Buissart
Modified: 2024-02-12 09:09 UTC (History)
20 users (show)

Fixed In Version: jss 5.1.0, jss 4.9.3
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service.
Clone Of:
Environment:
Last Closed: 2022-05-11 05:15:27 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Knowledge Base (Solution) 6956876 0 None None None 2022-09-13 11:50:06 UTC
Red Hat Product Errata RHSA-2022:1851 0 None None None 2022-05-10 13:49:26 UTC
Red Hat Product Errata RHSA-2024:0774 0 None None None 2024-02-12 09:09:14 UTC

Description Cedric Buissart 2022-01-20 10:25:49 UTC
It was found that JSS did not properly free up all the memory resulting of a TLS connection. This could be used by an attacker to force the invocation of Linux's Out-Of-Memory process, causing a denial of service.

Comment 8 Cedric Buissart 2022-02-09 16:56:56 UTC
Created jss tracking bugs for this issue:

Affects: fedora-all [bug 2052632]

Comment 14 errata-xmlrpc 2022-05-10 13:49:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2022:1851 https://access.redhat.com/errata/RHSA-2022:1851

Comment 15 Product Security DevOps Team 2022-05-11 05:15:25 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2021-4213

Comment 16 Petr Čech 2022-09-13 11:50:07 UTC
*** Bug 2011102 has been marked as a duplicate of this bug. ***

Comment 17 errata-xmlrpc 2024-02-12 09:09:11 UTC
This issue has been addressed in the following products:

  Red Hat Certificate System 10.4 for RHEL-8

Via RHSA-2024:0774 https://access.redhat.com/errata/RHSA-2024:0774


Note You need to log in before you can comment on or make changes to this bug.