RHSA-2021:3816HighCVSS 9.0

Red Hat Security Advisory: httpd:2.4 security update

Published
October 12, 2021
Last Modified
August 6, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2021-26691 — httpd: mod_session: Heap overflow via a crafted SessionHeader value CVE-2021-40438 — httpd: mod_proxy: SSRF via a crafted request uri-path containing "unix:"

🎯 Affected products86

  • Red Hat Enterprise Linux AppStream (v. 8)
  • httpd-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.aarch64 (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • httpd-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.ppc64le (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • httpd-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.s390x (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • httpd-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.src (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • httpd-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.x86_64 (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • httpd-debuginfo-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.aarch64 (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • httpd-debuginfo-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.ppc64le (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • httpd-debuginfo-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.s390x (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • httpd-debuginfo-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.x86_64 (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • httpd-debugsource-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.aarch64 (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • httpd-debugsource-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.ppc64le (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • httpd-debugsource-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.s390x (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • httpd-debugsource-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.x86_64 (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • httpd-devel-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.aarch64 (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • httpd-devel-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.ppc64le (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • httpd-devel-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.s390x (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • httpd-devel-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.x86_64 (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • httpd-filesystem-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.noarch (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • httpd-manual-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.noarch (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • httpd-tools-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.aarch64 (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • httpd-tools-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.ppc64le (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • httpd-tools-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.s390x (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • httpd-tools-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.x86_64 (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • httpd-tools-debuginfo-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.aarch64 (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • httpd-tools-debuginfo-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.ppc64le (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • httpd-tools-debuginfo-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.s390x (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • httpd-tools-debuginfo-0:2.4.37-39.module+el8.4.0+12865+a7065a39.1.x86_64 (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • mod_http2-0:1.15.7-3.module+el8.4.0+8625+d397f3da.aarch64 (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • mod_http2-0:1.15.7-3.module+el8.4.0+8625+d397f3da.ppc64le (httpd:2.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • +56 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. Workaround: Only configurations which use the "SessionEnv" directive (which is not widely used) are vulnerable to this flaw. SessionEnv is not enabled in default configuration of httpd package shipped with Red Hat Products. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

🔗 References (5)