Infinite loop in Apache Tomcat - CVE-2021-41079
Published: September 15, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop when processing certain TLS packets. A remote attacker can send a specially crafted packet to the application, consume all available system resources and cause denial of service conditions.
Successful exploitation of vulnerability requires that Apache Tomcat is configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS.
Affected software
JBoss Web Server
Amazon Linux AMI
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Web Scripting
Ubuntu
openEuler
Dell Secure Connect Gateway
IBM UrbanCode Release
tomcat9 (Debian package)
tomcat9-docs (Ubuntu package)
libtomcat9-java (Ubuntu package)
tomcat9 (Ubuntu package)
libtomcat8-java (Ubuntu package)
tomcat8 (Ubuntu package)
tomcat8-docs (Ubuntu package)
Tomcat
javapackages-tools
tomcat
tomcat-help
tomcat-jsvc
libtomcat9-embed-java (Ubuntu package)
tomcat9-common (Ubuntu package)
tomcat-webapps
tomcat-servlet-4_0-api
tomcat-lib
tomcat-jsp-2_3-api
tomcat-javadoc
tomcat-el-3_0-api
tomcat-docs-webapp
tomcat-admin-webapps
IBM Engineering Requirements Management DOORS Next
Storage Copy Data Management
Storage Protect Plus Server
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
How to mitigate CVE-2021-41079
Dell Secure Connect Gateway - update to 5.12.00.10
JBoss Web Server - update to 5.5.1
IBM UrbanCode Release - update to 6.2.5.3
tomcat9 (Debian package) - addressed in versions 9.0.31-1~deb10u6, 9.0.43-2~deb11u2
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
tomcat9-docs (Ubuntu package) - addressed in versions Ubuntu Pro, 9.0.31-1ubuntu0.6
libtomcat9-java (Ubuntu package) - addressed in versions Ubuntu Pro, 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2, 9.0.31-1ubuntu0.6
tomcat9 (Ubuntu package) - addressed in versions Ubuntu Pro, 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2, 9.0.31-1ubuntu0.6
libtomcat8-java (Ubuntu package) - update to Ubuntu Pro
tomcat8 (Ubuntu package) - update to Ubuntu Pro
tomcat8-docs (Ubuntu package) - update to Ubuntu Pro
Tomcat - update to D.9.0.87.01
javapackages-tools - update to 2.0.1-13.1
Storage Copy Data Management - update to 2.2.23.0
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
tomcat - addressed in versions 9.0.10-21, 9.0.10-26
tomcat-help - addressed in versions 9.0.10-21, 9.0.10-26
tomcat-jsvc - addressed in versions 9.0.10-21, 9.0.10-26
libtomcat9-embed-java (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
tomcat9-common (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
tomcat-webapps - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat-servlet-4_0-api - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat-lib - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat-jsp-2_3-api - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat-javadoc - update to 9.0.36-3.71.1
tomcat-el-3_0-api - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat-docs-webapp - update to 9.0.36-3.71.1
tomcat-admin-webapps - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
Storage Protect Plus Server - update to 10.1.16.1
External References
Related Security Bulletins
- Denial of service in Apache Tomcat
- Denial of service in Red Hat JBoss Web Server
- Debian update for tomcat9
- Amazon Linux AMI update for tomcat8
- Multiple vulnerabilities in IBM UrbanCode Release
- Ubuntu update for tomcat9
- SUSE update for tomcat
- SUSE update for tomcat
- SUSE update for tomcat
- SUSE update for tomcat
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- Multiple vulnerabilities in Dell Unity, Dell UnityVSA, and Dell Unity XT
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS/DWA
- openEuler update for tomcat
- openEuler update for tomcat
- Multiple vulnerabilities in IBM Storage Protect Plus Server
- Multiple vulnerabilities in IBM Storage Copy Data Management
- Ubuntu update for tomcat8
- HP-UX update for Tomcat