Memory leak in envoy - CVE-2023-35945
Published: July 16, 2023
Vulnerability identifier: #VU78293
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-35945
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform DoS attack on the target system.
The vulnerability exists due memory leak when handling HTTP/2 requests within the nghttp2 codec. A remote attacker can send RST_STREAM immediately followed by the GOAWAY frames to the application and force memory leak.
Affected software
envoy
Dell EMC NetWorker vProxy
Amazon Linux AMI
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
openSUSE Leap
openEuler
Anolis OS
EcoStruxure Power Operation
nghttp2
OpenShift Service Mesh
ObjectScale
EMC ECS
skuba
skuba-update
nghttp2
libnghttp2-14-debuginfo-32bit
libnghttp2-14-32bit
nghttp2-debugsource
libnghttp2-14
libnghttp2-14-debuginfo
nghttp2-debuginfo
libnghttp2-devel
libnghttp2-14-32bit-debuginfo
libnghttp2_asio1-debuginfo
libnghttp2_asio-devel
libnghttp2_asio1
libnghttp2_asio1-32bit-debuginfo
libnghttp2_asio1-32bit
python3-nghttp2-debuginfo
python3-nghttp2
nghttp2-python-debugsource
libnghttp2
nghttp2-help
nghttp2-doc
caasp-release
release-notes-caasp
nodejs
Dell Secure Connect Gateway
RecoverPoint for VMs
Dell EMC VxRail Appliance
Dell EMC NetWorker vProxy
Amazon Linux AMI
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
openSUSE Leap
openEuler
Anolis OS
EcoStruxure Power Operation
nghttp2
OpenShift Service Mesh
ObjectScale
EMC ECS
skuba
skuba-update
nghttp2
libnghttp2-14-debuginfo-32bit
libnghttp2-14-32bit
nghttp2-debugsource
libnghttp2-14
libnghttp2-14-debuginfo
nghttp2-debuginfo
libnghttp2-devel
libnghttp2-14-32bit-debuginfo
libnghttp2_asio1-debuginfo
libnghttp2_asio-devel
libnghttp2_asio1
libnghttp2_asio1-32bit-debuginfo
libnghttp2_asio1-32bit
python3-nghttp2-debuginfo
python3-nghttp2
nghttp2-python-debugsource
libnghttp2
nghttp2-help
nghttp2-doc
caasp-release
release-notes-caasp
nodejs
Dell Secure Connect Gateway
RecoverPoint for VMs
Dell EMC VxRail Appliance
How to mitigate CVE-2023-35945
Install updates from vendor's website.
envoy - addressed in versions 1.23.11, 1.24.9, 1.25.8, 1.26.3
EcoStruxure Power Operation - update to 2024 CU2
nghttp2 - update to 1.55.1
OpenShift Service Mesh - addressed in versions 2.2.10, 2.3.6
ObjectScale - update to 1.4.0
skuba - update to 1.4.17-150100.3.70.1
skuba-update - update to 1.4.17-150100.3.70.1
nghttp2 - addressed in versions 1.33.0-1.1.7, 1.55.1-1
libnghttp2-14-debuginfo-32bit - update to 1.39.2-3.10.1
libnghttp2-14-32bit - addressed in versions 1.39.2-3.10.1, 1.40.0-150000.3.14.1, 1.40.0-150200.9.1
nghttp2-debugsource - addressed in versions 1.39.2-3.10.1, 1.40.0-150000.3.14.1, 1.40.0-150200.9.1
libnghttp2-14 - addressed in versions 1.39.2-3.10.1, 1.40.0-150000.3.14.1, 1.40.0-150200.9.1
libnghttp2-14-debuginfo - addressed in versions 1.39.2-3.10.1, 1.40.0-150000.3.14.1, 1.40.0-150200.9.1
nghttp2-debuginfo - addressed in versions 1.39.2-3.10.1, 1.40.0-150000.3.14.1, 1.40.0-150200.9.1
libnghttp2-devel - addressed in versions 1.39.2-3.10.1, 1.40.0-150000.3.14.1, 1.40.0-150200.9.1
libnghttp2-14-32bit-debuginfo - addressed in versions 1.40.0-150000.3.14.1, 1.40.0-150200.9.1
libnghttp2_asio1-debuginfo - addressed in versions 1.40.0-150000.3.14.1, 1.40.0-150200.9.1
libnghttp2_asio-devel - addressed in versions 1.40.0-150000.3.14.1, 1.40.0-150200.9.1
libnghttp2_asio1 - addressed in versions 1.40.0-150000.3.14.1, 1.40.0-150200.9.1
libnghttp2_asio1-32bit-debuginfo - update to 1.40.0-150200.9.1
libnghttp2_asio1-32bit - update to 1.40.0-150200.9.1
python3-nghttp2-debuginfo - update to 1.40.0-150200.9.1
python3-nghttp2 - update to 1.40.0-150200.9.1
nghttp2 - update to 1.40.0-150200.9.1
nghttp2-python-debugsource - update to 1.40.0-150200.9.1
nghttp2 - update to 1.41.0-3
libnghttp2 - update to 1.41.0-3
nghttp2-debuginfo - update to 1.41.0-3
nghttp2-debugsource - update to 1.41.0-3
libnghttp2-devel - update to 1.41.0-3
nghttp2-help - update to 1.41.0-3
nghttp2-doc - update to 1.57.0-1
nghttp2 - update to 1.57.0-1
libnghttp2-devel - update to 1.57.0-1
libnghttp2 - update to 1.57.0-1
EMC ECS - update to 3.8.1.1
caasp-release - update to 4.2.10-150100.24.55.2
release-notes-caasp - update to 4.2.20231122-150100.4.85.1
Dell Secure Connect Gateway - update to 5.20.00.10
RecoverPoint for VMs - update to 6.0.SP1.P1
Dell EMC VxRail Appliance - update to 8.0.120
nodejs - update to 18.12.1-1
Dell EMC NetWorker vProxy - addressed in versions 19.9.0.4, 19.10
EcoStruxure Power Operation - update to 2024 CU2
nghttp2 - update to 1.55.1
OpenShift Service Mesh - addressed in versions 2.2.10, 2.3.6
ObjectScale - update to 1.4.0
skuba - update to 1.4.17-150100.3.70.1
skuba-update - update to 1.4.17-150100.3.70.1
nghttp2 - addressed in versions 1.33.0-1.1.7, 1.55.1-1
libnghttp2-14-debuginfo-32bit - update to 1.39.2-3.10.1
libnghttp2-14-32bit - addressed in versions 1.39.2-3.10.1, 1.40.0-150000.3.14.1, 1.40.0-150200.9.1
nghttp2-debugsource - addressed in versions 1.39.2-3.10.1, 1.40.0-150000.3.14.1, 1.40.0-150200.9.1
libnghttp2-14 - addressed in versions 1.39.2-3.10.1, 1.40.0-150000.3.14.1, 1.40.0-150200.9.1
libnghttp2-14-debuginfo - addressed in versions 1.39.2-3.10.1, 1.40.0-150000.3.14.1, 1.40.0-150200.9.1
nghttp2-debuginfo - addressed in versions 1.39.2-3.10.1, 1.40.0-150000.3.14.1, 1.40.0-150200.9.1
libnghttp2-devel - addressed in versions 1.39.2-3.10.1, 1.40.0-150000.3.14.1, 1.40.0-150200.9.1
libnghttp2-14-32bit-debuginfo - addressed in versions 1.40.0-150000.3.14.1, 1.40.0-150200.9.1
libnghttp2_asio1-debuginfo - addressed in versions 1.40.0-150000.3.14.1, 1.40.0-150200.9.1
libnghttp2_asio-devel - addressed in versions 1.40.0-150000.3.14.1, 1.40.0-150200.9.1
libnghttp2_asio1 - addressed in versions 1.40.0-150000.3.14.1, 1.40.0-150200.9.1
libnghttp2_asio1-32bit-debuginfo - update to 1.40.0-150200.9.1
libnghttp2_asio1-32bit - update to 1.40.0-150200.9.1
python3-nghttp2-debuginfo - update to 1.40.0-150200.9.1
python3-nghttp2 - update to 1.40.0-150200.9.1
nghttp2 - update to 1.40.0-150200.9.1
nghttp2-python-debugsource - update to 1.40.0-150200.9.1
nghttp2 - update to 1.41.0-3
libnghttp2 - update to 1.41.0-3
nghttp2-debuginfo - update to 1.41.0-3
nghttp2-debugsource - update to 1.41.0-3
libnghttp2-devel - update to 1.41.0-3
nghttp2-help - update to 1.41.0-3
nghttp2-doc - update to 1.57.0-1
nghttp2 - update to 1.57.0-1
libnghttp2-devel - update to 1.57.0-1
libnghttp2 - update to 1.57.0-1
EMC ECS - update to 3.8.1.1
caasp-release - update to 4.2.10-150100.24.55.2
release-notes-caasp - update to 4.2.20231122-150100.4.85.1
Dell Secure Connect Gateway - update to 5.20.00.10
RecoverPoint for VMs - update to 6.0.SP1.P1
Dell EMC VxRail Appliance - update to 8.0.120
nodejs - update to 18.12.1-1
Dell EMC NetWorker vProxy - addressed in versions 19.9.0.4, 19.10
External References
Related Security Bulletins
- Denial of service in Envoy
- Amazon Linux AMI update for nghttp2
- Multiple vulnerabiltiies in Red Hat OpenShift Service Mesh Containers 2.3
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh 2.2
- SUSE update for nghttp2
- SUSE update for nghttp2
- SUSE update for nghttp2
- Multiple vulnerabilities in Dell Secure Connect Gateway
- SUSE update for Updates Cilium
- Dell EMC NetWorker vProxy update for third-party components
- openEuler update for nghttp2
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in Dell ECS
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in Dell RecoverPoint for Virtual Machines
- Amazon Linux AMI update for nodejs
- Amazon Linux AMI update for nghttp2
- Amazon Linux AMI update for ecs-service-connect-agent
- Anolis OS update for nghttp2
- Multiple vulnerabilities in Schneider Electric EcoStruxure Power Operation
- HTTP/2 memory leak in nghttp2