Unrated severityNVD Advisory· Published Jun 4, 2024· Updated Aug 2, 2024
Envoy affected by a crash in EnvoyQuicServerStream::OnInitialHeadersComplete()
CVE-2024-32974
Description
Envoy is a cloud-native, open source edge and service proxy. A crash was observed in EnvoyQuicServerStream::OnInitialHeadersComplete() with following call stack. It is a use-after-free caused by QUICHE continuing push request headers after StopReading() being called on the stream. As after StopReading(), the HCM's ActiveStream might have already be destroyed and any up calls from QUICHE could potentially cause use after free.
Affected products
1- Range: >= 1.30.0, <= 11.30.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/envoyproxy/envoy/security/advisories/GHSA-mgxp-7hhp-8299mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.