RHBA-2022:8077LowCVSS 7.5
Red Hat Bug Fix Advisory: pki-servlet-engine bug fix and enhancement update
🔗 CVE IDs covered (1)
📋 Description
CVE-2021-42340 — tomcat: OutOfMemoryError caused by HTTP upgrade connection leak could lead to DoS
🎯 Affected products4
- Red Hat Enterprise Linux AppStream (v. 9)
- pki-servlet-4.0-api-1:9.0.50-1.el9.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
- pki-servlet-engine-1:9.0.50-1.el9.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
- pki-servlet-engine-1:9.0.50-1.el9.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
🔗 References (4)
- selfhttps://access.redhat.com/errata/RHBA-2022:8077
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/9.1_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2060910
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhba-2022_8077.json