CVE-2021-41079: Apache Tomcat DoS with unexpected TLS packet
A flaw was found in Apache Tomcat. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet can trigger an infinite loop, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
Other sources
Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a denial of service.
Apache Tomcat did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a denial of service. This issue affects the version of Apache Tomcat 10.0.0-M1 to 10.0.2; 9.0.0-M1 to 9.0.43; 8.5.0 to 8.5.63.
Upstream commits: Tomcat 10.0.4: https://github.com/apache/tomcat/commit/34115fb3c83f6cd97772232316a492a4cc5729e0 Tomcat 9.0.44: https://github.com/apache/tomcat/commit/d4b340fa8feaf55831f9a59350578f7b6ca048b8 Tomcat 8.5.64: https://github.com/apache/tomcat/commit/b90d4fc1ff44f30e4b3aba622ba6677e3f003822
Reference: https://lists.apache.org/thread.html/rccdef0349fdf4fb73a4e4403095446d7fe6264e0a58e2df5c6799434%40%3Cannounce.tomcat.apache.org%3E
— Red Hat
Apache Tomcat is vulnerable to a denial of service, caused by improper input validation of TLS packets. By sending a specially-crafted TLS packet, a remote attacker could exploit this vulnerability to cause the application to enter into an infinite loop.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jws5-tomcatto a version that resolves this vulnerability.Fixed in 0:9.0.43-13.redhat_00013.1.el7 - Upgrade
Upgrade
redhat/jws5-tomcatto a version that resolves this vulnerability.Fixed in 0:9.0.43-13.redhat_00013.1.el8 - Upgrade
Upgrade
debian/tomcat9to a version that resolves this vulnerability.Fixed in 9.0.43-2~deb11u10Fixed in 9.0.43-2~deb11u12Fixed in 9.0.70-2Fixed in 9.0.95-1 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 10.0.4 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 9.0.44 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 8.5.64 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.0.4 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 8.5.64 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.44 - Compensating control
If unable to immediately upgrade, avoid configuring Tomcat to use NIO+OpenSSL or NIO2+OpenSSL for TLS, since the infinite-loop DoS is described specifically for those TLS configurations.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-41079.
What is the severity of CVE-2021-41079?
The severity of CVE-2021-41079 is high with a CVSS score of 7.5.
What is the affected software?
The affected software includes Apache Tomcat versions 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43, and 10.0.0-M1 to 10.0.2.
How can I fix CVE-2021-41079?
To fix CVE-2021-41079, you need to update Apache Tomcat to version 10.0.4, 9.0.44, or 8.5.64, depending on the version you are using.
Where can I find more information about CVE-2021-41079?
You can find more information about CVE-2021-41079 in the references section.