CVE-2021-29509: The fix for CVE-2019-16770 was incomplete. The original fix only protected existing connections that had already been accepted from having their requests starved by greedy persistent-connections saturating all threads in the same process. However, new connections may still be starved by greedy persistent-connections saturating all threads in all processes in the cluster. A puma server which received more concurrent keep-alive connections than the server had threads in its threadpool would service only a subset of connections, denying service to the unserved connections. Please stabilize 5.3.1.
amd64 stable
x86 stable. Maintainer(s), please cleanup. Security, please vote.
Cleanup done.
Thank you!
Unable to check for sanity: > no match for package: www-servers/puma-5.3.2
Unable to check for sanity: > no match for package: www-servers/puma-5.3.2-r1
GLSA request filed
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=74f54f14d9074878f0b2b711ab3064799b15e9cb commit 74f54f14d9074878f0b2b711ab3064799b15e9cb Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2022-08-14 21:41:58 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2022-08-14 21:43:20 +0000 [ GLSA 202208-28 ] Puma: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/794034 Bug: https://bugs.gentoo.org/817893 Bug: https://bugs.gentoo.org/833155 Bug: https://bugs.gentoo.org/836431 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: Sam James <sam@gentoo.org> glsa-202208-28.xml | 48 ++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 48 insertions(+)
GLSA done, all done.