PT-2024-25021 · Envoy · Envoy

Danzh2010

·

Published

2024-06-04

·

Updated

2024-07-11

·

CVE-2024-32974

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Envoy (affected versions not specified)
Description A crash was observed in EnvoyQuicServerStream::OnInitialHeadersComplete() due to a use-after-free issue. This occurs when QUICHE continues to push request headers after StopReading() is called on the stream. The ActiveStream in the HCM might be destroyed after StopReading(), and subsequent calls from QUICHE could cause a use-after-free error.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ENVOY-2024-32974
CVE-2024-32974
GHSA-MGXP-7HHP-8299

Affected Products

Envoy