Input validation error in gRPC - CVE-2024-11407

 

Input validation error in gRPC - CVE-2024-11407

Published: December 20, 2024


Vulnerability identifier: #VU101889
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-11407
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

gRPC
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
Red Hat Enterprise Linux for x86_64
Public Cloud Module
Python 3 Module
Basesystem Module
openSUSE Leap
openEuler
envoy
python-ruamel-yaml-clib (Red Hat package)
python-colorama (Red Hat package)
python-galaxy-importer (Red Hat package)
python3.11-galaxy-importer (Red Hat package)
python-dataclasses (Red Hat package)
python-commonmark (Red Hat package)
python-ruamel-yaml (Red Hat package)
rubygem-foreman_leapp (Red Hat package)
python-enrich (Red Hat package)
rubygem-foreman_maintain (Red Hat package)
python3.11-yarl (Red Hat package)
grpc-debuginfo
grpc
python3-grpcio
grpc-plugins
grpc-devel
grpc-debugsource
upb-devel
grpc-devel-debuginfo
grpc-source
libgrpc++1_60-debuginfo
libgrpc37-debuginfo
libgrpc1_60
libgrpc++1_60
libupb37
libgrpc37
libgrpc1_60-debuginfo
libupb37-debuginfo
python311-grpcio-debuginfo
python311-grpcio
python-grpcio-debugsource
python-grpcio (Red Hat package)
python-bracex (Red Hat package)
python3.11-aiohappyeyeballs (Red Hat package)
ansible-automation-platform-installer (Red Hat package)
automation-gateway (Red Hat package)
python3.11-django-ansible-base (Red Hat package)
ansible-core (Red Hat package)
python3.11-aiodns (Red Hat package)
python3.11-aiohttp (Red Hat package)
foreman (Red Hat package)
foreman-installer (Red Hat package)
python3.11-pulpcore (Red Hat package)
automation-controller (Red Hat package)
rubygem-katello (Red Hat package)
ansible-lint (Red Hat package)
satellite (Red Hat package)
python-tenacity (Red Hat package)
python-wcmatch (Red Hat package)
python-rich (Red Hat package)
rubygem-foreman_theme_satellite (Red Hat package)
Ansible Automation Platform

How to mitigate CVE-2024-11407

Install updates from vendor's website.

gRPC - update to 1.68.0
envoy - addressed in versions 1.33.10, 1.34.8, 1.35.4
python-ruamel-yaml-clib (Red Hat package) - update to 0.2.7-4.el9pc
python-colorama (Red Hat package) - update to 0.4.4-7.el9pc
python-galaxy-importer (Red Hat package) - addressed in versions 0.4.19-3.el8pc, 0.4.19-3.el9pc
python3.11-galaxy-importer (Red Hat package) - addressed in versions 0.4.27-1.el8ap, 0.4.27-1.el9ap
python-dataclasses (Red Hat package) - update to 0.8-7.el9pc
python-commonmark (Red Hat package) - update to 0.9.1-9.el9pc
python-ruamel-yaml (Red Hat package) - update to 0.17.21-5.el9pc
rubygem-foreman_leapp (Red Hat package) - addressed in versions 1.2.3-1.el8sat, 1.2.3-1.el9sat
python-enrich (Red Hat package) - update to 1.2.6-7.el9pc
rubygem-foreman_maintain (Red Hat package) - addressed in versions 1.7.11-1.el8sat, 1.7.11-1.el9sat
python3.11-yarl (Red Hat package) - addressed in versions 1.13.1-1.el8ap, 1.13.1-1.el9ap
grpc-debuginfo - update to 1.60.0-5
grpc - update to 1.60.0-5
python3-grpcio - update to 1.60.0-5
grpc-plugins - update to 1.60.0-5
grpc-devel - update to 1.60.0-5
grpc-debugsource - update to 1.60.0-5
grpc-devel - addressed in versions 1.60.0-150400.8.8.1, 1.60.0-150500.11.8.1, 1.60.0-150600.15.3.1
upb-devel - addressed in versions 1.60.0-150400.8.8.1, 1.60.0-150500.11.8.1, 1.60.0-150600.15.3.1
grpc-devel-debuginfo - addressed in versions 1.60.0-150400.8.8.1, 1.60.0-150500.11.8.1, 1.60.0-150600.15.3.1
grpc-source - addressed in versions 1.60.0-150400.8.8.1, 1.60.0-150500.11.8.1, 1.60.0-150600.15.3.1
libgrpc++1_60-debuginfo - addressed in versions 1.60.0-150400.8.8.1, 1.60.0-150500.11.8.1, 1.60.0-150600.15.3.1
libgrpc37-debuginfo - addressed in versions 1.60.0-150400.8.8.1, 1.60.0-150500.11.8.1, 1.60.0-150600.15.3.1
libgrpc1_60 - addressed in versions 1.60.0-150400.8.8.1, 1.60.0-150500.11.8.1, 1.60.0-150600.15.3.1
grpc-debuginfo - addressed in versions 1.60.0-150400.8.8.1, 1.60.0-150500.11.8.1, 1.60.0-150600.15.3.1
grpc-debugsource - addressed in versions 1.60.0-150400.8.8.1, 1.60.0-150500.11.8.1, 1.60.0-150600.15.3.1
libgrpc++1_60 - addressed in versions 1.60.0-150400.8.8.1, 1.60.0-150500.11.8.1, 1.60.0-150600.15.3.1
libupb37 - addressed in versions 1.60.0-150400.8.8.1, 1.60.0-150500.11.8.1, 1.60.0-150600.15.3.1
libgrpc37 - addressed in versions 1.60.0-150400.8.8.1, 1.60.0-150500.11.8.1, 1.60.0-150600.15.3.1
libgrpc1_60-debuginfo - addressed in versions 1.60.0-150400.8.8.1, 1.60.0-150500.11.8.1, 1.60.0-150600.15.3.1
libupb37-debuginfo - addressed in versions 1.60.0-150400.8.8.1, 1.60.0-150500.11.8.1, 1.60.0-150600.15.3.1
python311-grpcio-debuginfo - addressed in versions 1.60.1-150400.9.10.1, 1.60.1-150500.12.6.1, 1.60.1-150600.16.8.1
python311-grpcio - addressed in versions 1.60.1-150400.9.10.1, 1.60.1-150500.12.6.1, 1.60.1-150600.16.8.1
python-grpcio-debugsource - addressed in versions 1.60.1-150400.9.10.1, 1.60.1-150500.12.6.1, 1.60.1-150600.16.8.1
python-grpcio (Red Hat package) - addressed in versions 1.68.1-1.el8pc, 1.68.1-1.el9pc
python-bracex (Red Hat package) - update to 2.2.1-6.el9pc
Ansible Automation Platform - addressed in versions 2.4, 2.5
python3.11-aiohappyeyeballs (Red Hat package) - addressed in versions 2.4.4-1.el8ap, 2.4.4-1.el9ap
ansible-automation-platform-installer (Red Hat package) - addressed in versions 2.5-7.el8ap, 2.5-7.el9ap
automation-gateway (Red Hat package) - addressed in versions 2.5.20250115-1.el8ap, 2.5.20250115-1.el9ap
python3.11-django-ansible-base (Red Hat package) - addressed in versions 2.5.20250115-1.el8ap, 2.5.20250115-1.el9ap
ansible-core (Red Hat package) - addressed in versions 2.16.14-2.el8ap, 2.16.14-2.el9ap
python3.11-aiodns (Red Hat package) - addressed in versions 3.2.0-1.el8ap, 3.2.0-1.el9ap
python3.11-aiohttp (Red Hat package) - addressed in versions 3.10.11-1.el8ap, 3.10.11-1.el9ap
foreman (Red Hat package) - addressed in versions 3.12.0.2-1.el8sat, 3.12.0.2-1.el9sat
foreman-installer (Red Hat package) - addressed in versions 3.12.0.4-1.el8sat, 3.12.0.4-1.el9sat
python3.11-pulpcore (Red Hat package) - addressed in versions 3.49.29-1.el8ap, 3.49.29-1.el9ap
automation-controller (Red Hat package) - addressed in versions 4.6.6-1.el8ap, 4.6.6-1.el9ap
rubygem-katello (Red Hat package) - addressed in versions 4.14.0.6-1.el8sat, 4.14.0.6-1.el9sat
ansible-lint (Red Hat package) - update to 5.4.0-1.el9pc
satellite (Red Hat package) - addressed in versions 6.16.2-1.el8sat, 6.16.2-1.el9sat
python-tenacity (Red Hat package) - update to 7.0.0-5.el9pc
python-wcmatch (Red Hat package) - update to 8.3-5.el9pc
python-rich (Red Hat package) - update to 13.3.1-7.el9pc
rubygem-foreman_theme_satellite (Red Hat package) - addressed in versions 13.3.3-1.el8sat, 13.3.3-1.el9sat

External References

Related Security Bulletins