Envoy Experiences Crash Due to Integer Underflow in PeekRegion Implementation
CVE-2024-32975
7.5HIGH
What is CVE-2024-32975?
A vulnerability has been identified in the Envoy Edge and Service Proxy, where a crash occurs in the QuicheDataReader::PeekVarInt62Length() function. This issue arises from an integer underflow within the QuicStreamSequencerBuffer::PeekRegion() method, which may lead to unreliable service operation. The vulnerability potentially disrupts the normal functioning of applications utilizing Envoy, making it essential for users to assess and address the risks associated with these versions.
