Red Hat Security Advisory: httpd:2.4 security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2021-26691 — httpd: mod_session: Heap overflow via a crafted SessionHeader value CVE-2021-40438 — httpd: mod_proxy: SSRF via a crafted request uri-path containing "unix:"
🎯 Affected products86
- Red Hat Enterprise Linux AppStream (v. 8)
- httpd-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.aarch64 (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- httpd-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.ppc64le (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- httpd-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.s390x (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- httpd-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.src (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- httpd-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.x86_64 (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- httpd-debuginfo-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.aarch64 (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- httpd-debuginfo-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.ppc64le (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- httpd-debuginfo-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.s390x (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- httpd-debuginfo-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.x86_64 (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- httpd-debugsource-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.aarch64 (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- httpd-debugsource-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.ppc64le (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- httpd-debugsource-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.s390x (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- httpd-debugsource-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.x86_64 (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- httpd-devel-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.aarch64 (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- httpd-devel-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.ppc64le (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- httpd-devel-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.s390x (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- httpd-devel-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.x86_64 (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- httpd-filesystem-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.noarch (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- httpd-manual-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.noarch (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- httpd-tools-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.aarch64 (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- httpd-tools-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.ppc64le (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- httpd-tools-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.s390x (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- httpd-tools-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.x86_64 (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- httpd-tools-debuginfo-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.aarch64 (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- httpd-tools-debuginfo-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.ppc64le (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- httpd-tools-debuginfo-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.s390x (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- httpd-tools-debuginfo-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.x86_64 (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- mod_http2-0:1.15.7-3.module+el8.4.0+8625+d397f3da.aarch64 (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- mod_http2-0:1.15.7-3.module+el8.4.0+8625+d397f3da.ppc64le (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- +56 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. Workaround: Only configurations which use the "SessionEnv" directive (which is not widely used) are vulnerable to this flaw. SessionEnv is not enabled in default configuration of httpd package shipped with Red Hat Products. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2021:3816
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1966732
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2005117
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_3816.json