CVE-2021-41524
published 2021-10-05CVE-2021-41524: While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server…
PriorityP355high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
24.98%
97.7th percentile
While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | — | — |
| apache_software_foundation | apache_http_server | — | — |
| debian | apache2 | < apache2 2.4.50-1 (bookworm) | apache2 2.4.50-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cm1_httpd_2.4.51-1_on_cbl_mariner_1.0 | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | instantis_enterprisetrack | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_cisco7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
null pointer dereference in h2 fuzzing
vendor_msrc·2021-10-12·CVSS 7.5
CVE-2021-41524 [HIGH] CWE-476 null pointer dereference in h2 fuzzing
null pointer dereference in h2 fuzzing
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
apache: apache
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/
Cisco
Apache HTTP Server Vulnerabilities: October 2021
vendor_cisco·2021-10-07·CVSS 7.5
CVE-2021-41524 [HIGH] CWE-22 Apache HTTP Server Vulnerabilities: October 2021
Apache HTTP Server Vulnerabilities: October 2021
On October 5, 2021 and October 7, 2021, the Apache Software Foundation released two security announcements for the Apache HTTP Server that disclosed the following vulnerabilities:
CVE-2021-41524: Null Pointer Dereference Vulnerability
CVE-2021-41773: Path Traversal and Remote Code Execution Vulnerability
CVE-2021-42013: Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
For descriptions of these vulnerabilities, see the Apache Security Announcement. For additional information, see the Cisco TALOS blog post, Threat Advisory: Apache HTTP Server zero-day vulnerability opens door for attackers.
Cisco investigated its product line and concluded that no Cisco products are affecte
Red Hat
httpd: NULL pointer dereference via crafted request during HTTP/2 request processing
vendor_redhat·2021-10-05·CVSS 7.5
CVE-2021-41524 [HIGH] CWE-476 httpd: NULL pointer dereference via crafted request during HTTP/2 request processing
httpd: NULL pointer dereference via crafted request during HTTP/2 request processing
While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project.
Statement: This issue only affects Apache HTTP Server 2.4.49 and Red Hat JBoss Core Services Apache HTTP Server 2.4.37 SP9, earlier versions are not affected. Therefore this issue does not affect the other versions of Apache HTTP Server shipped with Red Hat products.
Package: httpd (Red Hat Enterprise Linux 6) - Not affected
Package: httpd (Red Hat Enterprise Linux 7) - Not affected
Package: httpd:2.4/httpd (R
Debian
CVE-2021-41524: apache2 - While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected duri...
vendor_debian·2021·CVSS 7.5
CVE-2021-41524 [HIGH] CVE-2021-41524: apache2 - While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected duri...
While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project.
Scope: local
bookworm: resolved (fixed in 2.4.50-1)
bullseye: resolved
forky: resolved (fixed in 2.4.50-1)
sid: resolved (fixed in 2.4.50-1)
trixie: resolved (fixed in 2.4.50-1)
Cisco
Apache HTTP Server Vulnerabilities: October 2021
vendor_cisco
CVE-2021-42013 Apache HTTP Server Vulnerabilities: October 2021
CVE-2021-42013: Apache HTTP Server Vulnerabilities: October 2021
On October 5, 2021 and October 7, 2021, the Apache Software Foundation released two security announcements for the Apache HTTP Server that disclosed the following vulnerabilities:
CVE-2021-41524: Null Pointer Dereference Vulnerability
CVE-2021-41773: Path Traversal and Remote Code Execution Vulnerability
CVE-2021-42013: Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
For descriptions of these vulnerabilities, see the Apache Security Announcement. For additional information, see the Cisco TALOS blog post, Threat Advisory: Apache HTTP Server zero-day vulnerability opens door for attackers.
Cisco investigated its product line and concluded that no Cisco produc
Cisco
Apache HTTP Server Vulnerabilities: October 2021
vendor_cisco
CVE-2021-41773 Apache HTTP Server Vulnerabilities: October 2021
CVE-2021-41773: Apache HTTP Server Vulnerabilities: October 2021
On October 5, 2021 and October 7, 2021, the Apache Software Foundation released two security announcements for the Apache HTTP Server that disclosed the following vulnerabilities:
CVE-2021-41524: Null Pointer Dereference Vulnerability
CVE-2021-41773: Path Traversal and Remote Code Execution Vulnerability
CVE-2021-42013: Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
For descriptions of these vulnerabilities, see the Apache Security Announcement. For additional information, see the Cisco TALOS blog post, Threat Advisory: Apache HTTP Server zero-day vulnerability opens door for attackers.
Cisco investigated its product line and concluded that no Cisco produc
Cisco
Apache HTTP Server Vulnerabilities: October 2021
vendor_cisco
CVE-2021-41524 Apache HTTP Server Vulnerabilities: October 2021
CVE-2021-41524: Apache HTTP Server Vulnerabilities: October 2021
On October 5, 2021 and October 7, 2021, the Apache Software Foundation released two security announcements for the Apache HTTP Server that disclosed the following vulnerabilities:
CVE-2021-41524: Null Pointer Dereference Vulnerability
CVE-2021-41773: Path Traversal and Remote Code Execution Vulnerability
CVE-2021-42013: Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
For descriptions of these vulnerabilities, see the Apache Security Announcement. For additional information, see the Cisco TALOS blog post, Threat Advisory: Apache HTTP Server zero-day vulnerability opens door for attackers.
Cisco investigated its product line and concluded that no Cisco produc
GHSA
GHSA-f29c-hjcq-ww2f: While fuzzing the 2
ghsa_unreviewed·2022-05-24
CVE-2021-41524 [HIGH] CWE-476 GHSA-f29c-hjcq-ww2f: While fuzzing the 2
While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project.
OSV
CVE-2021-41524: While fuzzing the 2
osv·2021-10-05·CVSS 7.5
CVE-2021-41524 [HIGH] CVE-2021-41524: While fuzzing the 2
While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project.
No detection rules found.
No public exploits indexed.
Tenable
CVE-2021-41773: Path Traversal Zero-Day in Apache HTTP Server Exploited
blogs_tenable·2021-10-05·CVSS 9.8
[CRITICAL] CVE-2021-41773: Path Traversal Zero-Day in Apache HTTP Server Exploited
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2021-41524 httpd: NULL pointer dereference via crafted request during HTTP/2 request processing
bugzilla·2021-10-05·CVSS 7.5
CVE-2021-41524 [HIGH] CVE-2021-41524 httpd: NULL pointer dereference via crafted request during HTTP/2 request processing
CVE-2021-41524 httpd: NULL pointer dereference via crafted request during HTTP/2 request processing
While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project.
References:
https://httpd.apache.org/security/vulnerabilities_24.html
https://lists.apache.org/thread.html/rc30f96fa07346fa6bdd73f3e172b8964ec9a7d49351b4f60422fc469@%3Cannounce.apache.org%3E
Discussion:
Created httpd tracking bugs for this issue:
Affects: fedora-all [bug 2010935]
---
This issue has been addressed in the following products:
Red Hat JBoss Core Services
Via RHSA-2022:7144 https
http://www.openwall.com/lists/oss-security/2021/10/05/1https://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DSM6UWQICBJ2TU727RENU3HBKEAFLT6T/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EUVJVRJRBW5QVX4OY3NOHZDQ3B3YOTSG/https://security.gentoo.org/glsa/202208-20https://security.netapp.com/advisory/ntap-20211029-0009/https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-pathtrv-LAzg68cZhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttp://www.openwall.com/lists/oss-security/2021/10/05/1https://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DSM6UWQICBJ2TU727RENU3HBKEAFLT6T/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EUVJVRJRBW5QVX4OY3NOHZDQ3B3YOTSG/https://security.gentoo.org/glsa/202208-20https://security.netapp.com/advisory/ntap-20211029-0009/https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-pathtrv-LAzg68cZhttps://www.oracle.com/security-alerts/cpujan2022.html
2021-10-05
Published