ALAS2-2021-1678

Related Vulnerabilities: CVE-2021-31618  

A null pointer de-reference was found in the way httpd handled specially crafted HTTP/2 request. A remote attacker could use this flaw to crash the httpd child process, causing temporary denial of service. (CVE-2021-31618)

ALAS2-2021-1678


Amazon Linux 2 Security Advisory: ALAS-2021-1678
Advisory Release Date: 2021-07-01 01:04 Pacific
Advisory Updated Date: 2021-07-01 20:27 Pacific
Severity: Important
References: CVE-2021-31618 

Issue Overview:

A null pointer de-reference was found in the way httpd handled specially crafted HTTP/2 request. A remote attacker could use this flaw to crash the httpd child process, causing temporary denial of service. (CVE-2021-31618)


Affected Packages:

mod_http2


Issue Correction:
Run yum update mod_http2 to update your system.

New Packages:
aarch64:
    mod_http2-1.15.19-1.amzn2.0.1.aarch64
    mod_http2-debuginfo-1.15.19-1.amzn2.0.1.aarch64

i686:
    mod_http2-1.15.19-1.amzn2.0.1.i686
    mod_http2-debuginfo-1.15.19-1.amzn2.0.1.i686

src:
    mod_http2-1.15.19-1.amzn2.0.1.src

x86_64:
    mod_http2-1.15.19-1.amzn2.0.1.x86_64
    mod_http2-debuginfo-1.15.19-1.amzn2.0.1.x86_64