Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Tue, 05 Oct 2021 09:02:50 +0000
From: Stefan Eissing <>
Subject: CVE-2021-41524: Apache HTTP Server: null pointer dereference in h2

Severity: moderate


While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing,
allowing an external source to DoS the server. This requires a specially crafted request. 

The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project.


Disable the HTTP/2 protocol.


Apache httpd team would like to thank LI ZHI XIN from NSFocus Security Team for reporting this issue.


Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.