Input validation error in gRPC - CVE-2023-32731

 

Input validation error in gRPC - CVE-2023-32731

Published: August 21, 2023


Vulnerability identifier: #VU79797
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32731
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to insufficient validation of user-supplied input when parsing HTTP2 requests. When gRPC HTTP2 stack raised a header size exceeded error, it skipped parsing the rest of the HPACK frame. This caused any HPACK table mutations to also be skipped, resulting in a desynchronization of HPACK tables between sender and receiver. This could lead to requests from the proxy being interpreted as containing headers from different proxy clients, leading to an information leak that can be used for privilege escalation or data exfiltration.


Affected software

gRPC
Amazon Linux AMI
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Workstation Extension 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
openSUSE Leap Micro
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Public Cloud Module
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Package Hub 15
Python 3 Module
Basesystem Module
Development Tools Module
openSUSE Leap
IBM Operations Analytics Predictive Insights
IBM Security Guardium Key Lifecycle Manager (GKLM)
IBM Intelligent Operations Center
IBM Sterling B2B Integrator
WebSphere Remote Server
IBM Security Verify Governance
IBM MQ Operator
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Tivoli Business Service Manager
IBM Cloud Application Performance Management (APM)
HPE Telco IP Mediation E-Media
IBM Maximo Application Suite
IBM Cloud Pak for Business Automation
IBM Robotic Process Automation
Juniper Cloud Native Router
IBM Sterling File Gateway
Db2 Big SQL
IBM OpenPages with Watson
dashDB Local
IBM Application Suite - IBM Asset Data Dictionary Component
Answer Retrieval for Watson Discovery On Prem
IBM Cloud Pak for Watson AIOps
Storage Resource Manager
Storage Protect Server
IBM supplied MQ Advanced container images
Robotic Process Automation for Cloud Pak
IBM DB2
rhc-worker-playbook (Red Hat package)
opencensus-proto-source
python311-abseil
grpc
libgrpc1_60
libupb37
grpc-devel
grpc-debugsource
libupb37-debuginfo
libgrpc37-debuginfo
upb-devel
libgrpc++1_60-debuginfo
libgrpc++1_60
grpc-debuginfo
libgrpc1_60-debuginfo
libgrpc37
grpc-devel-debuginfo
grpc-source
python311-grpcio-debuginfo
python-grpcio-debugsource
python311-grpcio
python311-protobuf
protobuf-java
libprotobuf25_1_0-debuginfo
libprotobuf-lite25_1_0
protobuf-devel-debuginfo
libprotobuf25_1_0
libprotobuf-lite25_1_0-64bit-debuginfo
protobuf-debugsource
libprotobuf25_1_0-64bit
libprotoc25_1_0-64bit
libprotobuf25_1_0-64bit-debuginfo
libprotobuf-lite25_1_0-64bit
libprotoc25_1_0-64bit-debuginfo
libprotobuf25_1_0-32bit
libprotoc25_1_0-debuginfo
protobuf-devel
libprotoc25_1_0
libprotobuf-lite25_1_0-debuginfo
libprotoc25_1_0-32bit-debuginfo
libprotoc25_1_0-32bit
libprotobuf25_1_0-32bit-debuginfo
libprotobuf-lite25_1_0-32bit-debuginfo
libprotobuf-lite25_1_0-32bit
libabsl2308_0_0
libabsl2308_0_0-debuginfo
abseil-cpp-devel
libabsl2308_0_0-32bit-debuginfo
abseil-cpp-debugsource
libabsl2308_0_0-32bit
libabsl2308_0_0-64bit-debuginfo
libabsl2308_0_0-64bit
libre2-11-32bit
re2-debugsource
libre2-11-32bit-debuginfo
libre2-11-64bit
libre2-11-64bit-debuginfo
libre2-11-debuginfo
libre2-11
re2-devel
watsonx.data
IBM Cloud Pak System
Dell EMC Storage Monitoring and Reporting (SMR)
Junos cRPD

How to mitigate CVE-2023-32731

Install updates from vendor's website.

gRPC - update to 1.53.0
IBM Sterling File Gateway - addressed in versions 6.2.0.5.1, 6.2.1.1.1
IBM Sterling B2B Integrator - addressed in versions 6.2.0.5.1, 6.2.1.1.1
Db2 Big SQL - update to 7.6.2
dashDB Local - update to 11.5.9.0
rhc-worker-playbook (Red Hat package) - update to 0.1.10-1.el9_5
opencensus-proto-source - update to 0.3.0+git.20200721-150400.9.3.1
IBM Application Suite - IBM Asset Data Dictionary Component - update to 1.1.9
python311-abseil - update to 1.4.0-150400.9.3.1
grpc - update to 1.56.2-10
libgrpc1_60 - update to 1.60.0-150400.8.3.2
libupb37 - update to 1.60.0-150400.8.3.2
grpc-devel - update to 1.60.0-150400.8.3.2
grpc-debugsource - update to 1.60.0-150400.8.3.2
libupb37-debuginfo - update to 1.60.0-150400.8.3.2
libgrpc37-debuginfo - update to 1.60.0-150400.8.3.2
upb-devel - update to 1.60.0-150400.8.3.2
libgrpc++1_60-debuginfo - update to 1.60.0-150400.8.3.2
libgrpc++1_60 - update to 1.60.0-150400.8.3.2
grpc-debuginfo - update to 1.60.0-150400.8.3.2
libgrpc1_60-debuginfo - update to 1.60.0-150400.8.3.2
libgrpc37 - update to 1.60.0-150400.8.3.2
grpc-devel-debuginfo - update to 1.60.0-150400.8.3.2
grpc-source - update to 1.60.0-150400.8.3.2
python311-grpcio-debuginfo - update to 1.60.0-150400.9.3.2
python-grpcio-debugsource - update to 1.60.0-150400.9.3.2
python311-grpcio - update to 1.60.0-150400.9.3.2
watsonx.data - update to 2.0.3
IBM MQ Operator - addressed in versions 2.0.13, 2.4.2
IBM Cloud Pak System - addressed in versions 2.3.4.1, 2.3.5.0
Answer Retrieval for Watson Discovery On Prem - update to 2.12.0
IBM Cloud Pak for Watson AIOps - update to 4.1.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.7.1
python311-protobuf - update to 4.25.1-150400.9.3.1
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.1.0
Storage Resource Manager - update to 5.0.1.0
IBM Tivoli Business Service Manager - update to 6.2.0.5.4
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
Storage Protect Server - update to 8.1.22
HPE Telco IP Mediation E-Media - update to 8.5.1
IBM Maximo Application Suite - addressed in versions 8.9.9, 8.10.4
IBM supplied MQ Advanced container images - update to 9.3.0.10-r1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.24, 23.0.1.2
IBM Robotic Process Automation - addressed in versions 21.0.7.9, 23.0.10
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.9, 23.0.10
Junos cRPD - update to 23.4R1
Juniper Cloud Native Router - update to 23.4R1
protobuf-java - update to 25.1-150400.9.3.1
libprotobuf25_1_0-debuginfo - update to 25.1-150400.9.3.1
libprotobuf-lite25_1_0 - update to 25.1-150400.9.3.1
protobuf-devel-debuginfo - update to 25.1-150400.9.3.1
libprotobuf25_1_0 - update to 25.1-150400.9.3.1
libprotobuf-lite25_1_0-64bit-debuginfo - update to 25.1-150400.9.3.1
protobuf-debugsource - update to 25.1-150400.9.3.1
libprotobuf25_1_0-64bit - update to 25.1-150400.9.3.1
libprotoc25_1_0-64bit - update to 25.1-150400.9.3.1
libprotobuf25_1_0-64bit-debuginfo - update to 25.1-150400.9.3.1
libprotobuf-lite25_1_0-64bit - update to 25.1-150400.9.3.1
libprotoc25_1_0-64bit-debuginfo - update to 25.1-150400.9.3.1
libprotobuf25_1_0-32bit - update to 25.1-150400.9.3.1
libprotoc25_1_0-debuginfo - update to 25.1-150400.9.3.1
protobuf-devel - update to 25.1-150400.9.3.1
libprotoc25_1_0 - update to 25.1-150400.9.3.1
libprotobuf-lite25_1_0-debuginfo - update to 25.1-150400.9.3.1
libprotoc25_1_0-32bit-debuginfo - update to 25.1-150400.9.3.1
libprotoc25_1_0-32bit - update to 25.1-150400.9.3.1
libprotobuf25_1_0-32bit-debuginfo - update to 25.1-150400.9.3.1
libprotobuf-lite25_1_0-32bit-debuginfo - update to 25.1-150400.9.3.1
libprotobuf-lite25_1_0-32bit - update to 25.1-150400.9.3.1
libabsl2308_0_0 - update to 20230802.1-150400.10.4.1
libabsl2308_0_0-debuginfo - update to 20230802.1-150400.10.4.1
abseil-cpp-devel - update to 20230802.1-150400.10.4.1
libabsl2308_0_0-32bit-debuginfo - update to 20230802.1-150400.10.4.1
abseil-cpp-debugsource - update to 20230802.1-150400.10.4.1
libabsl2308_0_0-32bit - update to 20230802.1-150400.10.4.1
libabsl2308_0_0-64bit-debuginfo - update to 20230802.1-150400.10.4.1
libabsl2308_0_0-64bit - update to 20230802.1-150400.10.4.1
libre2-11-32bit - update to 20240201-150400.9.3.1
re2-debugsource - update to 20240201-150400.9.3.1
libre2-11-32bit-debuginfo - update to 20240201-150400.9.3.1
libre2-11-64bit - update to 20240201-150400.9.3.1
libre2-11-64bit-debuginfo - update to 20240201-150400.9.3.1
libre2-11-debuginfo - update to 20240201-150400.9.3.1
libre2-11 - update to 20240201-150400.9.3.1
re2-devel - update to 20240201-150400.9.3.1

External References

Related Security Bulletins