Envoy Experiences Crash Due to Integer Underflow in PeekRegion Implementation
CVE-2024-32975

7.5HIGH

Key Information:

Vendor

Envoy

Status
Vendor
CVE Published:
4 June 2024

What is CVE-2024-32975?

A vulnerability has been identified in the Envoy Edge and Service Proxy, where a crash occurs in the QuicheDataReader::PeekVarInt62Length() function. This issue arises from an integer underflow within the QuicStreamSequencerBuffer::PeekRegion() method, which may lead to unreliable service operation. The vulnerability potentially disrupts the normal functioning of applications utilizing Envoy, making it essential for users to assess and address the risks associated with these versions.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.