PT-2021-7027 · Apache+5 · Apache Tomcat+5

David Frankson

+1

·

Published

2021-03-10

·

Updated

2026-03-26

·

CVE-2021-41079

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 8.5.0 through 8.5.63 Apache Tomcat versions 9.0.0-M1 through 9.0.43 Apache Tomcat versions 10.0.0-M1 through 10.0.2
Description The issue arises from insufficient validation of incoming TLS packets. When configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet can trigger an infinite loop, resulting in a denial of service. This can be exploited by a remote attacker to cause a denial of service using a specially crafted packet.
Recommendations For Apache Tomcat versions 8.5.0 through 8.5.63, consider disabling the use of NIO+OpenSSL or NIO2+OpenSSL for TLS until a patch is available. For Apache Tomcat versions 9.0.0-M1 through 9.0.43, consider disabling the use of NIO+OpenSSL or NIO2+OpenSSL for TLS until a patch is available. For Apache Tomcat versions 10.0.0-M1 through 10.0.2, consider disabling the use of NIO+OpenSSL or NIO2+OpenSSL for TLS until a patch is available. As a temporary workaround, consider restricting access to the TLS configuration to minimize the risk of exploitation.

Exploit

Fix

DoS

Infinite Loop

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1993
ALT-PU-2025-9146
BDU:2022-02994
BIT-TOMCAT-2021-41079
CVE-2021-41079
DLA-2764-1
DSA-4986-1
GHSA-59G9-7GFX-C72P
MGASA-2021-0485
OESA-2021-1393
OESA-2022-1622
OPENSUSE-SU-2021:1490-1
OPENSUSE-SU-2021:3672-1
OPENSUSE-SU-2021_1490-1
OPENSUSE-SU-2021_3672-1
OPENSUSE-SU-2024:11618-1
OPENSUSE-SU-2024:13441-1
RHSA-2021:3741
ROSA-SA-2023-2258
SUSE-SU-2021:3602-1
SUSE-SU-2021:3669-1
SUSE-SU-2021:3670-1
SUSE-SU-2021:3672-1
SUSE-SU-2026:1058-1
USN-5360-1
USN-6943-1

Affected Products

Alt Linux
Apache Tomcat
Astra Linux
Linuxmint
Suse
Ubuntu