RHSA-2022:0258: Important: httpd:2.4 security update
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.Security Fix(es): httpd: modlua: Possible buffer overflow when parsing multipart content (CVE-2021-44790) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+13806+b30d9eec.1 - Upgrade
Upgrade
redhat/httpd-filesystemto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+13806+b30d9eec.1 - Upgrade
Upgrade
redhat/httpd-manualto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+13806+b30d9eec.1 - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+13806+b30d9eec.1 - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+13806+b30d9eec.1 - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+13806+b30d9eec.1 - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+13806+b30d9eec.1 - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+13806+b30d9eec.1 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+13807+c8c001ae.3 - Upgrade
Upgrade
redhat/httpd-filesystemto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+13807+c8c001ae.3 - Upgrade
Upgrade
redhat/httpd-manualto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+13807+c8c001ae.3 - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+13807+c8c001ae.3 - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+13807+c8c001ae.3 - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+13807+c8c001ae.3 - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+13807+c8c001ae.3 - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+13807+c8c001ae.3 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+13808+dea277df.3 - Upgrade
Upgrade
redhat/httpd-filesystemto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+13808+dea277df.3 - Upgrade
Upgrade
redhat/httpd-manualto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+13808+dea277df.3 - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+13808+dea277df.3 - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+13808+dea277df.3 - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+13808+dea277df.3 - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+13808+dea277df.3 - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+13808+dea277df.3 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+13806+b30d9eec.1.aa - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+13806+b30d9eec.1.aa - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+13806+b30d9eec.1.aa - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+13806+b30d9eec.1.aa - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+13806+b30d9eec.1.aa - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+13806+b30d9eec.1.aa - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+13807+c8c001ae.3.aa - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+13807+c8c001ae.3.aa - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+13807+c8c001ae.3.aa - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+13807+c8c001ae.3.aa - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+13807+c8c001ae.3.aa - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+13807+c8c001ae.3.aa - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+13808+dea277df.3.aa - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+13808+dea277df.3.aa - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+13808+dea277df.3.aa - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+13808+dea277df.3.aa - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+13808+dea277df.3.aa - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+13808+dea277df.3.aa - Upgrade
Upgrade
httpd (Apache HTTP Server) / mod_luato a version that resolves this vulnerability.Patch CVE-2021-44790
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:0258?
The severity of RHSA-2022:0258 is categorized as important due to a potential buffer overflow vulnerability in mod_lua.
How do I fix RHSA-2022:0258?
To fix RHSA-2022:0258, update the httpd package to version 2.4.37-43 or later.
What packages are affected by RHSA-2022:0258?
The affected packages include httpd, httpd-filesystem, httpd-manual, httpd-debuginfo, httpd-debugsource, httpd-devel, and httpd-tools.
What vulnerability does RHSA-2022:0258 address?
RHSA-2022:0258 addresses CVE-2021-44790, which involves a possible buffer overflow when parsing multipart content.
Is there a workaround for RHSA-2022:0258?
There is no official workaround for RHSA-2022:0258; the recommended action is to apply the security update.