CVE-2021-4213
Alma Linux vulnerability analysis and mitigation

Overview

CVE-2021-4213 is a vulnerability discovered in JSS (Java Security Services) where the software fails to properly free up memory during TLS connections. The vulnerability was identified as a memory leak issue that causes wasted memory to accumulate in the server's RAM over time (NVD, Debian Tracker).

Technical details

The vulnerability stems from a memory leak in TLS connections where JSS does not properly free up all memory resources. The issue involves multiple relationships that point at each other, creating a cycle that prevents the JSSEngineReferenceImpl's finalizer from running and clearing native resources. During testing with Tomcat 8.5, most instances did not call cleanup, resulting in leaked JNI resources including sslfd, readbuf, and write_buf (GitHub Commit).

Impact

The vulnerability can lead to server memory saturation as wasted memory builds up over time. This could allow an attacker to force the invocation of Linux's Out-Of-Memory (OOM) process, resulting in a denial of service condition (Debian Tracker, Bugzilla).

Mitigation and workarounds

The issue has been fixed in multiple versions of JSS. The fix involved breaking the cycle at SSLAlertEvent.engine, which allowed JSSEngineReferenceImpl to be garbage collected and the finalizer to run properly. The fix was implemented through two commits that addressed the memory management issues (GitHub Commit, Additional Fix).

Additional resources


SourceThis report was generated using AI

Related Alma Linux vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-13020HIGH8.8
  • NixOSNixOS
  • firefox
NoYesNov 11, 2025
CVE-2025-59088HIGH8.6
  • Rocky LinuxRocky Linux
  • python3-pyusb
NoYesNov 12, 2025
CVE-2025-13019HIGH8.1
  • NixOSNixOS
  • MozillaFirefox-devel
NoYesNov 11, 2025
CVE-2025-13018HIGH8.1
  • NixOSNixOS
  • firefox
NoYesNov 11, 2025
CVE-2025-59089MEDIUM5.9
  • Rocky LinuxRocky Linux
  • idm:DL1::ipa-python-compat
NoYesNov 12, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management