RHSA-2021:2290: Important: nginx:1.16 security update
nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage. Security Fix(es): nginx: Off-by-one in ngxresolvercopy() when labels are followed by a pointer to a root domain name (CVE-2021-23017) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/nginxto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1 - Upgrade
Upgrade
redhat/nginx-all-modulesto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1 - Upgrade
Upgrade
redhat/nginx-filesystemto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1 - Upgrade
Upgrade
redhat/nginx-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1 - Upgrade
Upgrade
redhat/nginx-debugsourceto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1 - Upgrade
Upgrade
redhat/nginx-mod-http-image-filterto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1 - Upgrade
Upgrade
redhat/nginx-mod-http-image-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1 - Upgrade
Upgrade
redhat/nginx-mod-http-perlto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1 - Upgrade
Upgrade
redhat/nginx-mod-http-perl-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1 - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filterto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1 - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1 - Upgrade
Upgrade
redhat/nginx-mod-mailto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1 - Upgrade
Upgrade
redhat/nginx-mod-mail-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1 - Upgrade
Upgrade
redhat/nginx-mod-streamto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1 - Upgrade
Upgrade
redhat/nginx-mod-stream-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1 - Upgrade
Upgrade
redhat/nginxto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1 - Upgrade
Upgrade
redhat/nginx-all-modulesto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1 - Upgrade
Upgrade
redhat/nginx-filesystemto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1 - Upgrade
Upgrade
redhat/nginx-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1 - Upgrade
Upgrade
redhat/nginx-debugsourceto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1 - Upgrade
Upgrade
redhat/nginx-mod-http-image-filterto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1 - Upgrade
Upgrade
redhat/nginx-mod-http-image-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1 - Upgrade
Upgrade
redhat/nginx-mod-http-perlto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1 - Upgrade
Upgrade
redhat/nginx-mod-http-perl-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1 - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filterto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1 - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1 - Upgrade
Upgrade
redhat/nginx-mod-mailto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1 - Upgrade
Upgrade
redhat/nginx-mod-mail-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1 - Upgrade
Upgrade
redhat/nginx-mod-streamto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1 - Upgrade
Upgrade
redhat/nginx-mod-stream-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1 - Upgrade
Upgrade
redhat/nginxto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1 - Upgrade
Upgrade
redhat/nginx-all-modulesto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1 - Upgrade
Upgrade
redhat/nginx-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1 - Upgrade
Upgrade
redhat/nginx-debugsourceto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1 - Upgrade
Upgrade
redhat/nginx-filesystemto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1 - Upgrade
Upgrade
redhat/nginx-mod-http-image-filterto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1 - Upgrade
Upgrade
redhat/nginx-mod-http-image-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1 - Upgrade
Upgrade
redhat/nginx-mod-http-perlto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1 - Upgrade
Upgrade
redhat/nginx-mod-http-perl-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1 - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filterto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1 - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1 - Upgrade
Upgrade
redhat/nginx-mod-mailto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1 - Upgrade
Upgrade
redhat/nginx-mod-mail-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1 - Upgrade
Upgrade
redhat/nginx-mod-streamto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1 - Upgrade
Upgrade
redhat/nginx-mod-stream-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1 - Upgrade
Upgrade
redhat/nginxto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1.aa - Upgrade
Upgrade
redhat/nginx-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1.aa - Upgrade
Upgrade
redhat/nginx-debugsourceto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-image-filterto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-image-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-perlto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-perl-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filterto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1.aa - Upgrade
Upgrade
redhat/nginx-mod-mailto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1.aa - Upgrade
Upgrade
redhat/nginx-mod-mail-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1.aa - Upgrade
Upgrade
redhat/nginx-mod-streamto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1.aa - Upgrade
Upgrade
redhat/nginx-mod-stream-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-2.module+el8.4.0+11155+68135136.1.aa - Upgrade
Upgrade
redhat/nginxto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1.aa - Upgrade
Upgrade
redhat/nginx-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1.aa - Upgrade
Upgrade
redhat/nginx-debugsourceto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-image-filterto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-image-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-perlto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-perl-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filterto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1.aa - Upgrade
Upgrade
redhat/nginx-mod-mailto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1.aa - Upgrade
Upgrade
redhat/nginx-mod-mail-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1.aa - Upgrade
Upgrade
redhat/nginx-mod-streamto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1.aa - Upgrade
Upgrade
redhat/nginx-mod-stream-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.2.0+11154+636e4c3b.1.aa - Upgrade
Upgrade
redhat/nginxto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1.aa - Upgrade
Upgrade
redhat/nginx-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1.aa - Upgrade
Upgrade
redhat/nginx-debugsourceto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-image-filterto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-image-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-perlto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-perl-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filterto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1.aa - Upgrade
Upgrade
redhat/nginx-mod-mailto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1.aa - Upgrade
Upgrade
redhat/nginx-mod-mail-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1.aa - Upgrade
Upgrade
redhat/nginx-mod-streamto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1.aa - Upgrade
Upgrade
redhat/nginx-mod-stream-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.1.0+11153+6c3a40a9.1.aa - Upgrade
Upgrade
nginxto a version that resolves this vulnerability.Fixed in 1.16Patch CVE-2021-23017
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:2290?
The severity of RHSA-2021:2290 is classified as important.
How do I fix RHSA-2021:2290?
To fix RHSA-2021:2290, update the nginx package to version 1.16.1-2.module+el8.4.0+11155+68135136.1 or later.
What systems are affected by RHSA-2021:2290?
RHSA-2021:2290 affects Red Hat Enterprise Linux 8 installations running nginx.
What specific vulnerability is addressed in RHSA-2021:2290?
RHSA-2021:2290 addresses an off-by-one vulnerability in ngx_resolver_copy(), categorized under CVE-2021-23017.
Is there a workaround for RHSA-2021:2290 if I can't apply the patch immediately?
There are no official workarounds recommended for RHSA-2021:2290; applying the update is advised.