RHSA-2021:2258: Important: rh-nginx118-nginx security update
nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage. Security Fix(es): nginx: Off-by-one in ngxresolvercopy() when labels are followed by a pointer to a root domain name (CVE-2021-23017) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:2258?
The severity of RHSA-2021:2258 is classified as important.
How do I fix RHSA-2021:2258?
To fix RHSA-2021:2258, update to nginx version 1.18.0-3.el7 or higher.
What vulnerabilities are addressed in RHSA-2021:2258?
RHSA-2021:2258 addresses an off-by-one vulnerability in the ngx_resolver_copy() function.
Which nginx versions are affected by RHSA-2021:2258?
Versions of nginx prior to 1.18.0-3.el7 are affected by RHSA-2021:2258.
Is there a specific package I need to upgrade for RHSA-2021:2258?
You need to upgrade the rh-nginx118-nginx package to remediate RHSA-2021:2258.