CVE-2021-43980

unknown
Published 2022-09-29 · Modified 2024-03-11
CVSS v3
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v2
VIR risk

Description

The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0.0-M1 to 9.0.60 and 8.5.0 to 8.5.77 that could cause client connections to share an Http11Processor instance resulting in responses, or part responses, to be received by the wrong client.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2021-43980

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2021-43980.html

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed9.0.62-1
debian debianbullseyefixed9.0.43-2~deb11u4
debian debianforkyfixed9.0.62-1
debian debiansidfixed9.0.62-1
debian debiantrixiefixed9.0.62-1

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.apache.tomcat:tomcat>=8.5.0,<8.5.788.5.78
java Mavenorg.apache.tomcat:tomcat>=9.0.0-M1,<9.0.629.0.62
java Mavenorg.apache.tomcat:tomcat>=10.0.0-M1,<10.0.2010.0.20
java Mavenorg.apache.tomcat:tomcat>=10.1.0-M1,<10.1.0-M1410.1.0-M14

References

Verify integrity in audit chain (admin only). AS-IS.