Infinite loop in Apache Tomcat - CVE-2021-41079

 

Infinite loop in Apache Tomcat - CVE-2021-41079

Published: September 15, 2021


Vulnerability identifier: #VU56634
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-41079
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop when processing certain TLS packets. A remote attacker can send a specially crafted packet to the application, consume all available system resources and cause denial of service conditions.

Successful exploitation of vulnerability requires that Apache Tomcat is configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS.


Affected software

Apache Tomcat
JBoss Web Server
Amazon Linux AMI
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Web Scripting
Ubuntu
openEuler
Dell Secure Connect Gateway
IBM UrbanCode Release
tomcat9 (Debian package)
tomcat9-docs (Ubuntu package)
libtomcat9-java (Ubuntu package)
tomcat9 (Ubuntu package)
libtomcat8-java (Ubuntu package)
tomcat8 (Ubuntu package)
tomcat8-docs (Ubuntu package)
Tomcat
javapackages-tools
tomcat
tomcat-help
tomcat-jsvc
libtomcat9-embed-java (Ubuntu package)
tomcat9-common (Ubuntu package)
tomcat-webapps
tomcat-servlet-4_0-api
tomcat-lib
tomcat-jsp-2_3-api
tomcat-javadoc
tomcat-el-3_0-api
tomcat-docs-webapp
tomcat-admin-webapps
IBM Engineering Requirements Management DOORS Next
Storage Copy Data Management
Storage Protect Plus Server
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)

How to mitigate CVE-2021-41079

Install updates from vendor's website.

Apache Tomcat - addressed in versions 8.5.64, 9.0.44, 10.0.4
Dell Secure Connect Gateway - update to 5.12.00.10
JBoss Web Server - update to 5.5.1
IBM UrbanCode Release - update to 6.2.5.3
tomcat9 (Debian package) - addressed in versions 9.0.31-1~deb10u6, 9.0.43-2~deb11u2
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
tomcat9-docs (Ubuntu package) - addressed in versions Ubuntu Pro, 9.0.31-1ubuntu0.6
libtomcat9-java (Ubuntu package) - addressed in versions Ubuntu Pro, 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2, 9.0.31-1ubuntu0.6
tomcat9 (Ubuntu package) - addressed in versions Ubuntu Pro, 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2, 9.0.31-1ubuntu0.6
libtomcat8-java (Ubuntu package) - update to Ubuntu Pro
tomcat8 (Ubuntu package) - update to Ubuntu Pro
tomcat8-docs (Ubuntu package) - update to Ubuntu Pro
Tomcat - update to D.9.0.87.01
javapackages-tools - update to 2.0.1-13.1
Storage Copy Data Management - update to 2.2.23.0
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
tomcat - addressed in versions 9.0.10-21, 9.0.10-26
tomcat-help - addressed in versions 9.0.10-21, 9.0.10-26
tomcat-jsvc - addressed in versions 9.0.10-21, 9.0.10-26
libtomcat9-embed-java (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
tomcat9-common (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
tomcat-webapps - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat-servlet-4_0-api - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat-lib - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat-jsp-2_3-api - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat-javadoc - update to 9.0.36-3.71.1
tomcat-el-3_0-api - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat-docs-webapp - update to 9.0.36-3.71.1
tomcat-admin-webapps - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
Storage Protect Plus Server - update to 10.1.16.1

External References

Related Security Bulletins