null pointer dereference in h2 fuzzing
Published Oct 5, 2021
7.5
HIGHCVSS 3.1
EPSS 25.17%
Description
While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project.
Affected products
-
- Version 2.4.49StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache HTTP Server | n/a |
|
Configuration 1
- 2.4.49
Configuration 2
- 34
- 35
Configuration 3
- 17.1
- 17.2
- 17.3
Configuration 4
- n/a
No data.
JBoss Core Services for RHEL 8
jbcs-httpd24-httpd-0:2.4.51-28.el8jbcs
Fixed · RHSA-2022:7143
JBoss Core Services on RHEL 7
jbcs-httpd24-httpd-0:2.4.51-28.el7jbcs
Fixed · RHSA-2022:7143
Red Hat Enterprise Linux 6
httpd
Not affected
Red Hat Enterprise Linux 7
httpd
Not affected
Red Hat Enterprise Linux 8
httpd:2.4/httpd
Not affected
Red Hat Enterprise Linux 9
httpd
Not affected
Red Hat JBoss Enterprise Application Platform 6
httpd
Out of support scope
Red Hat Software Collections
httpd24-httpd
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Core Services for RHEL 8 | jbcs-httpd24-httpd-0:2.4.51-28.el8jbcs | Fixed | RHSA-2022:7143 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-httpd-0:2.4.51-28.el7jbcs | Fixed | RHSA-2022:7143 |
| Red Hat Enterprise Linux 6 | httpd | Not affected | n/a |
| Red Hat Enterprise Linux 7 | httpd | Not affected | n/a |
| Red Hat Enterprise Linux 8 | httpd:2.4/httpd | Not affected | n/a |
| Red Hat Enterprise Linux 9 | httpd | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | httpd | Out of support scope | n/a |
| Red Hat Software Collections | httpd24-httpd | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Disable the HTTP/2 protocol.
Red Hat statement
This issue only affects Apache HTTP Server 2.4.49 and Red Hat JBoss Core Services Apache HTTP Server 2.4.37 SP9, earlier versions are not affected. Therefore this issue does not affect the other versions of Apache HTTP Server shipped with Red Hat products.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (34 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 25.17% (0.25170) | 97.87th | v5 (v2026.06.15) |
| Jun 15, 2026 | 24.98% (0.24982) | 97.63th | v5 (v2026.06.15) |
| May 26, 2026 | 3.96% (0.03961) | 88.52th | v4 (v2025.03.14) |
| Nov 21, 2025 | 7.10% (0.07103) | 91.15th | v4 (v2025.03.14) |
| Nov 18, 2025 | 11.80% (0.11804) | 93.02th | v4 (v2025.03.14) |
| Aug 31, 2025 | 6.77% (0.06767) | 90.92th | v4 (v2025.03.14) |
| Aug 22, 2025 | 8.62% (0.08615) | 92.04th | v4 (v2025.03.14) |
| Mar 30, 2025 | 6.59% (0.06586) | 90.25th | v4 (v2025.03.14) |
| Mar 29, 2025 | 57.32% (0.57323) | 97.33th | v4 (v2025.03.14) |
| Mar 24, 2025 | 6.59% (0.06586) | 90.25th | v4 (v2025.03.14) |
| Mar 23, 2025 | 30.82% (0.30822) | 96.19th | v4 (v2025.03.14) |
| Mar 17, 2025 | 6.59% (0.06586) | 90.47th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.87% (0.00871) | 83.11th | v3 (v2023.03.01) |
| Jun 20, 2024 | 0.87% (0.00871) | 82.49th | v3 (v2023.03.01) |
| May 11, 2024 | 0.61% (0.00615) | 78.63th | v3 (v2023.03.01) |
| Mar 22, 2024 | 0.60% (0.00597) | 77.94th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.60% (0.00597) | 75.93th | v3 (v2023.03.01) |
| Sep 4, 2023 | 0.63% (0.00634) | 76.47th | v3 (v2023.03.01) |
| May 27, 2023 | 0.65% (0.00653) | 76.48th | v3 (v2023.03.01) |
| May 13, 2023 | 0.56% (0.00558) | 74.34th | v3 (v2023.03.01) |
| Apr 28, 2023 | 0.48% (0.00482) | 72.30th | v3 (v2023.03.01) |
| Mar 18, 2023 | 0.55% (0.00550) | 74.01th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.47% (0.00471) | 71.81th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.86% (0.01859) | 77.22th | v2 (v2022.01.01) |
| Aug 14, 2022 | 1.86% (0.01859) | 76.05th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.74% (0.01742) | 74.10th | v2 (v2022.01.01) |
| Feb 8, 2022 | 19.03% (0.19026) | 93.69th | v2 (v2022.01.01) |
| Feb 4, 2022 | 11.66% (0.11664) | 88.85th | v2 (v2022.01.01) |
| Feb 3, 2022 | 16.61% (0.16605) | 90.26th | v1 |
| Jan 6, 2022 | 16.61% (0.16605) | 90.14th | v1 |
| Oct 30, 2021 | 4.25% (0.04249) | 83.71th | v1 |
| Oct 13, 2021 | 3.06% (0.03065) | 81.33th | v1 |
| Oct 8, 2021 | 1.04% (0.01040) | 64.14th | v1 |
| Oct 6, 2021 | 0.62% (0.00624) | 44.78th | v1 |
References (12)
- http://www.openwall.com/lists/oss-security/2021/10/05/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2021-41524 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2010934 Issue Tracking
- https://httpd.apache.org/security/vulnerabilities_24.html x_refsource_MISCVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DSM6UWQICBJ2TU727RENU3HBKEAFLT6T/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EUVJVRJRBW5QVX4OY3NOHZDQ3B3YOTSG/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2021-41524
- https://security.gentoo.org/glsa/202208-20 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20211029-0009/ x_refsource_CONFIRMThird Party Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-pathtrv-LAzg68cZ vendor-advisoryx_refsource_CISCOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2021-41524
- https://www.oracle.com/security-alerts/cpujan2022.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.