[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    [oss-security] CVE-2021-42340: Apache Tomcat: DoS via memory leak with WebSocket connections
From:       Mark Thomas <markt () apache ! org>
Date:       2021-10-14 14:27:04
Message-ID: 45b1d9ce-3088-112e-132e-bba47ad22054 () apache ! org
[Download RAW message or body]

The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 
10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a 
memory leak. The object introduced to collect metrics for HTTP upgrade 
connections was not released for WebSocket connections once the 
connection was closed. This created a memory leak that, over time, could 
lead to a denial of service via an OutOfMemoryError.

References:

https://lists.apache.org/thread.html/r83a35be60f06aca2065f188ee542b9099695d57ced2e70e0885f905c%40%3Cannounce.tomcat.apache.org%3E



[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic