Bug 1191326 (CVE-2021-41524)

Summary: VUL-0: CVE-2021-41524: apache2: null pointer dereference in h2 fuzzing
Product: [Novell Products] SUSE Security Incidents Reporter: Robert Frohl <rfrohl>
Component: IncidentsAssignee: Petr Gajdos <pgajdos>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P5 - None    
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/311740
Found By: --- Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Robert Frohl 2021-10-05 11:50:34 UTC
moderate: null pointer dereference in h2 fuzzing (CVE-2021-41524)

    While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing,

    allowing an external source to DoS the server. This requires a specially crafted request.

    The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project.

    Acknowledgements: Apache httpd team would like to thank LI ZHI XIN from NSFocus Security Team for reporting this issue.
    Reported to security team	2021-09-17
    fixed by r1893655 in 2.4.x	2021-09-26
    Update 2.4.50 released	2021-10-04
    Affects	2.4.49

Comment 1 Petr Gajdos 2021-10-05 11:57:59 UTC
2.4.50 is on its way to Factory.