Candidate: CVE-2021-42340 PublicDate: 2021-10-14 20:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42340 https://www.openwall.com/lists/oss-security/2021/10/14/1 https://github.com/apache/tomcat/commit/80f1438ec45e77a07b96419808971838d259eb47 (9.0.54) https://github.com/apache/tomcat/commit/d27535bdee95d252418201eb21e9d29476aa6b6a (8.5.72) https://lists.apache.org/thread.html/r83a35be60f06aca2065f188ee542b9099695d57ced2e70e0885f905c%40%3Cannounce.tomcat.apache.org%3E Description: The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_tomcat9: upstream_tomcat9: needs-triage trusty_tomcat9: ignored (out of standard support) xenial_tomcat9: ignored (out of standard support) bionic_tomcat9: needed focal_tomcat9: needed hirsute_tomcat9: ignored (reached end-of-life) impish_tomcat9: needed jammy_tomcat9: needs-triage devel_tomcat9: needs-triage Patches_tomcat8: upstream_tomcat8: needs-triage esm-infra/xenial_tomcat8: needed trusty_tomcat8: ignored (out of standard support) xenial_tomcat8: ignored (out of standard support) bionic_tomcat8: needed