PT-2024-2769 · Envoy+1 · Envoy+1

Phlax

+1

·

Published

2024-02-09

·

Updated

2026-01-21

·

CVE-2024-23325

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Envoy versions prior to 1.26.7 Envoy versions prior to 1.27.3 Envoy versions prior to 1.28.1 Envoy versions prior to 1.29.1
Description The issue is related to Envoy crashing in Proxy protocol when using an address type that isn’t supported by the OS. Specifically, Envoy is susceptible to crashing on a host with IPv6 disabled and a listener config with proxy protocol enabled when it receives a request where the client presents its IPv6 address. This is a valid scenario, as a client can present its IPv6 address to a target server even though the whole chain is connected via IPv4. The problem arises from an uncaught exception.
Recommendations For versions prior to 1.26.7, upgrade to version 1.26.7 or later. For versions prior to 1.27.3, upgrade to version 1.27.3 or later. For versions prior to 1.28.1, upgrade to version 1.28.1 or later. For versions prior to 1.29.1, upgrade to version 1.29.1 or later. As a temporary workaround, consider disabling the proxy protocol on hosts with IPv6 disabled until a patch is available.

Exploit

Fix

Improper Handling of Exceptional Conditions

Weakness Enumeration

Related Identifiers

BDU:2024-02906
BIT-ENVOY-2024-23325
CVE-2024-23325
GHSA-5M7C-MRWR-PM26

Affected Products

Envoy
Red Os