RHSA-2021:2278: Important: rh-nginx116-nginx security update
nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage. Security Fix(es): nginx: Off-by-one in ngxresolvercopy() when labels are followed by a pointer to a root domain name (CVE-2021-23017) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:2278?
The severity of RHSA-2021:2278 is classified as important.
How do I fix RHSA-2021:2278?
To fix RHSA-2021:2278, update to version 1.16.1-6.el7 or later of the affected packages.
Which versions of nginx are affected by RHSA-2021:2278?
Versions up to and including 1.16.1-6.el7 of nginx are affected by RHSA-2021:2278.
What is the CVE associated with RHSA-2021:2278?
RHSA-2021:2278 is associated with CVE-2021-23017, which describes an off-by-one error in nginx.
Which Red Hat packages need to be updated for RHSA-2021:2278?
The affected Red Hat packages include rh-nginx116-nginx and its related modules and debuginfo packages.