CVE-2021-41524
Published on: 10/05/2021 12:00:00 AM UTC
Last Modified on: 10/28/2022 01:51:00 PM UTC
Certain versions of Http Server from Apache contain the following vulnerability:
While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project.
- CVE-2021-41524 has been assigned by
secu[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
Apache Software Foundation - Apache HTTP Server version = 2.4.49
Vulnerability Patch/Work Around
- Disable the HTTP/2 protocol.
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVSS2 Score: 5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | NONE | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Apache HTTPD: Multiple Vulnerabilities (GLSA 202208-20) — Gentoo security | security.gentoo.org text/html |
![]() |
[SECURITY] Fedora 35 Update: httpd-2.4.50-1.fc35 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
Apache HTTP Server Vulnerabilties: October 2021 | tools.cisco.com text/html |
![]() |
Pony Mail! | lists.apache.org text/html |
![]() |
October 2021 Apache HTTP Server Vulnerabilities in NetApp Products | NetApp Product Security | security.netapp.com text/html |
![]() |
Pony Mail! | lists.apache.org text/html |
![]() |
oss-security - CVE-2021-41524: Apache HTTP Server: null pointer dereference in h2 fuzzing | www.openwall.com text/html |
![]() |
Oracle Critical Patch Update Advisory - January 2022 | www.oracle.com text/html |
![]() |
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project | httpd.apache.org text/html |
![]() |
No Description Provided | lists.fedoraproject.org Inactive LinkNot Archived |
![]() |
Related QID Numbers
- 150403 Apache HTTP Server NULL pointer dereference (CVE-2021-31618,CVE-2021-41524)
- 150404 Apache HTTP Server NULL pointer dereference (CVE-2021-41524)
- 182107 Debian Security Update for apache2 (CVE-2021-41524)
- 240794 Red Hat Update for JBoss Core Services (RHSA-2022:7143)
- 281962 Fedora Security Update for httpd (FEDORA-2021-5d2d4b6ac5)
- 352857 Amazon Linux Security Advisory for httpd24: ALAS-2021-1543
- 352858 Amazon Linux Security Advisory for httpd: ALAS2-2021-1716
- 500023 Alpine Linux Security Update for apache2
- 690017 Free Berkeley Software Distribution (FreeBSD) Security Update for apache httpd (25b78bdd-25b8-11ec-a341-d4c9ef517024)
- 710595 Gentoo Linux Apache HTTPD Multiple Vulnerabilities (GLSA 202208-20)
- 87465 Apache Hypertext Transfer Protocol Server (HTTP Server) Path Traversal and Null Pointer Dereference Vulnerabilities
- 900394 Common Base Linux Mariner (CBL-Mariner) Security Update for httpd (5961)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Apache | Http Server | 2.4.49 | All | All | All |
Operating System | Fedoraproject | Fedora | 34 | All | All | All |
Operating System | Fedoraproject | Fedora | 35 | All | All | All |
Application | Netapp | Cloud Backup | - | All | All | All |
Application | Oracle | Instantis Enterprisetrack | 17.1 | All | All | All |
Application | Oracle | Instantis Enterprisetrack | 17.2 | All | All | All |
Application | Oracle | Instantis Enterprisetrack | 17.3 | All | All | All |
- cpe:2.3:a:apache:http_server:2.4.49:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:instantis_enterprisetrack:17.2:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:instantis_enterprisetrack:17.3:*:*:*:*:*:*:*:
Discovery Credit
Apache httpd team would like to thank LI ZHI XIN from NSFocus Security Team for reporting this issue.
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-41524 : While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request… twitter.com/i/web/status/1… | 2021-10-05 08:44:16 |
![]() |
@iamamoose On the vulnerabilities page, the CVE-2021-41524 entry says "Affects <= 2.4.49" but just above it, it say… twitter.com/i/web/status/1… | 2021-10-05 10:29:06 |
![]() |
@iamamoose Update anyway, the moderate security vuln CVE-2021-41524 that was fixed as well is relevant to earlier versions too! | 2021-10-05 11:39:42 |
![]() |
CVE-2021-41524 (Latest articles about Ongoing threats) kkhacklabs.com/cve-2021-41524/ | 2021-10-05 12:00:03 |
![]() |
@Sp1l CVE-2021-41524 was also only 2.4.49, but due to an error was listed as Affects <=2.4.49 for a short time on t… twitter.com/i/web/status/1… | 2021-10-05 12:06:25 |
![]() |
CVE-2021-41524: Apache HTTP Server: null pointer dereference in h2 fuzzing: Posted by Stefan Eissing on Oct 05Sever… twitter.com/i/web/status/1… | 2021-10-05 13:22:02 |
![]() |
SIOSセキュリティブログを更新しました。 Apacheの脆弱性情報(Important: CVE-2021-41773, Moderate: CVE-2021-41524) #sios_tech #security… twitter.com/i/web/status/1… | 2021-10-05 18:43:00 |
![]() |
⚠️ Vulnerabilidades críticas en Apache Server ? CVE-2021-41773 y CVE-2021-41524 afectan Apache HTTP Server en su v… twitter.com/i/web/status/1… | 2021-10-05 18:51:07 |
![]() |
タイトルが不適切なため訂正しました。 Apache HTTP Serverの脆弱性情報(Important: CVE-2021-41773, Moderate: CVE-2021-41524) #sios_tech… twitter.com/i/web/status/1… | 2021-10-05 22:54:54 |
![]() |
[Vulnerability Report] deepwatch Threat Operations is tracking CVE-2021-41773 and CVE-2021-41524 regarding vulnerab… twitter.com/i/web/status/1… | 2021-10-05 23:29:18 |
![]() |
HTTP/2リクエストの処理における、NULLポインタ参照の脆弱性 (CVE-2021-41524) については、まだ Under investigation access.redhat.com/security/cve/C… | 2021-10-06 05:55:43 |
![]() |
Apache httpd の HTTP/2 の処理にサービスを妨害される問題 (CVE-2021-41524) [40154] sid.softek.jp/content/show/4… #SIDfm #脆弱性情報 | 2021-10-06 06:44:32 |
![]() |
CVE-2021-41524 While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request pr… twitter.com/i/web/status/1… | 2021-10-06 07:09:59 |
![]() |
CVE-2021-41524はNULLポインタ参照でサービス落ちる可能性があるだけか。 | 2021-10-06 07:11:05 |
![]() |
HTTP/2リクエストの処理における、NULLポインタ参照の脆弱性 (CVE-2021-41524)、jbcs-httpd24-httpd 以外は影響ない模様。 access.redhat.com/security/cve/C… | 2021-10-06 08:05:16 |
![]() |
素敵ブログ。 Apache HTTP Serverの脆弱性情報(Important: CVE-2021-41773, Moderate: CVE-2021-41524) (PoCつき) -… twitter.com/i/web/status/1… | 2021-10-06 12:40:33 |
![]() |
❓ Does your business use Apache web server? ??️ Patch it ASAP. Vulns: CVE-2021-41524 and CVE-2021-41773. A quick… twitter.com/i/web/status/1… | 2021-10-06 20:02:34 |
![]() |
Your organization uses Apache? You need to read this! CVE-2021-41773 warns of Path Traversal CVE-2021-41524 warns… twitter.com/i/web/status/1… | 2021-10-07 13:46:17 |
![]() |
Apache httpd の脆弱性に注意(CVE-2021-41524, CVE-2021-41773): Apache httpd に脆弱性が見つかり 2.4.50 がリリースされました(さらに修正版の 2... blog.cles.jp/item/12763?utm… | 2021-10-10 06:52:12 |
![]() |
CVE-2021-41524: Path Traversal vulnerability in Apache 2.4.49. | 2021-10-05 19:13:32 |