Use-after-free when tunneling TCP over HTTP, if downstream disconnects during upstream connection establishment
Package
envoy
(C++)
Affected versions
1.21.0 and earlier
Patched versions
1.18.6, 1.19.3, 1.20.2, 1.21.1
CVSS Score 6.1 AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L
Impact
Denial of Service (Crash)
Patches
Workarounds
No.
References
https://blog.envoyproxy.io
https://github.com/envoyproxy/envoy/releases
For more information
Open an issue in Envoy repo
Email us at envoy-security