We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-35942

Envoy's gRPC access log crash caused by the listener draining



Description

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12, gRPC access loggers using listener's global scope can cause a `use-after-free` crash when the listener is drained. Versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12 have a fix for this issue. As a workaround, disable gRPC access log or stop listener update.

Reserved 2023-06-20 | Published 2023-07-25 | Updated 2024-10-24 | Assigner GitHub_M


MEDIUM: 6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-416: Use After Free

Product status

>= 1.26.0, < 1.26.4
affected

>= 1.25.0, < 1.25.9
affected

>= 1.24.0, < 1.24.10
affected

< 1.23.12
affected

References

github.com/.../envoy/security/advisories/GHSA-69vr-g55c-v2v4

cve.org (CVE-2023-35942)

nvd.nist.gov (CVE-2023-35942)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2023-35942

Support options

Helpdesk Chat, Email, Knowledgebase
Telegram Chat
Subscribe to our newsletter to learn more about our work.