Envoy Proxy Crashes Due to Timing Issues
CVE-2024-23322
7.5HIGH
What is CVE-2024-23322?
The vulnerability present in Envoy, a high-performance edge/middle/service proxy, causes the service to crash under specific timeout configurations. When the parameters hedge_on_per_try_timeout, per_try_idle_timeout, and per_try_timeout are set simultaneously with compatible timeout intervals, the proxy fails. Upgrading to the specified patched versions, including 1.29.1, 1.28.1, 1.27.3, and 1.26.7, is highly recommended as there are no available workarounds for this vulnerability.
Affected Version(s)
envoy >= 1.29.0, < 1.29.1 < 1.29.0, 1.29.1
envoy >= 1.28.0, < 1.28.1 < 1.28.0, 1.28.1
envoy >= 1.27.0, < 1.27.3 < 1.27.0, 1.27.3
