RHSA-2021:4909: Critical: nss security update
Network Security Services (NSS) is a set of libraries designed to support the cross-platform development of security-enabled client and server applications.Security Fix(es): nss: Memory corruption in decodeECorDsaSignature with DSA signatures (and RSA-PSS) (CVE-2021-43527) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/nssto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4 - Upgrade
Upgrade
redhat/nss-debuginfoto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4 - Upgrade
Upgrade
redhat/nss-debugsourceto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4 - Upgrade
Upgrade
redhat/nss-develto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4 - Upgrade
Upgrade
redhat/nss-softoknto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4 - Upgrade
Upgrade
redhat/nss-softokn-debuginfoto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4 - Upgrade
Upgrade
redhat/nss-softokn-develto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4 - Upgrade
Upgrade
redhat/nss-softokn-freeblto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4 - Upgrade
Upgrade
redhat/nss-softokn-freebl-debuginfoto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4 - Upgrade
Upgrade
redhat/nss-softokn-freebl-develto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4 - Upgrade
Upgrade
redhat/nss-sysinitto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4 - Upgrade
Upgrade
redhat/nss-sysinit-debuginfoto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4 - Upgrade
Upgrade
redhat/nss-toolsto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4 - Upgrade
Upgrade
redhat/nss-tools-debuginfoto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4 - Upgrade
Upgrade
redhat/nss-utilto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4 - Upgrade
Upgrade
redhat/nss-util-debuginfoto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4 - Upgrade
Upgrade
redhat/nss-util-develto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4 - Upgrade
Upgrade
redhat/nssto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4.aa - Upgrade
Upgrade
redhat/nss-debuginfoto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4.aa - Upgrade
Upgrade
redhat/nss-debugsourceto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4.aa - Upgrade
Upgrade
redhat/nss-develto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4.aa - Upgrade
Upgrade
redhat/nss-softoknto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4.aa - Upgrade
Upgrade
redhat/nss-softokn-debuginfoto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4.aa - Upgrade
Upgrade
redhat/nss-softokn-develto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4.aa - Upgrade
Upgrade
redhat/nss-softokn-freeblto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4.aa - Upgrade
Upgrade
redhat/nss-softokn-freebl-debuginfoto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4.aa - Upgrade
Upgrade
redhat/nss-softokn-freebl-develto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4.aa - Upgrade
Upgrade
redhat/nss-sysinitto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4.aa - Upgrade
Upgrade
redhat/nss-sysinit-debuginfoto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4.aa - Upgrade
Upgrade
redhat/nss-toolsto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4.aa - Upgrade
Upgrade
redhat/nss-tools-debuginfoto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4.aa - Upgrade
Upgrade
redhat/nss-utilto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4.aa - Upgrade
Upgrade
redhat/nss-util-debuginfoto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4.aa - Upgrade
Upgrade
redhat/nss-util-develto a version that resolves this vulnerability.Fixed in 3.67.0-7.el8_4.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:4909?
The severity of RHSA-2021:4909 is classified as critical due to the memory corruption vulnerability in Network Security Services.
How do I fix RHSA-2021:4909?
To fix RHSA-2021:4909, update to the packages nss and related components to version 3.67.0-7.el8_4 or later.
What is the impact of RHSA-2021:4909?
The impact of RHSA-2021:4909 includes potential memory corruption that could allow an attacker to execute arbitrary code.
Which software versions are affected by RHSA-2021:4909?
Software versions affected by RHSA-2021:4909 include nss prior to version 3.67.0-7.el8_4.
Is there a workaround for RHSA-2021:4909?
There are no known workarounds for RHSA-2021:4909; upgrading to the patched version is recommended.