Infinite loop in envoy - CVE-2024-32976
Published: June 5, 2024
Vulnerability identifier: #VU91152
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-32976
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop. A remote attacker can consume all available system resources and cause denial of service conditions.
Affected software
envoy
Amazon Linux AMI
Istio
OpenShift Service Mesh
Amazon Linux AMI
Istio
OpenShift Service Mesh
How to mitigate CVE-2024-32976
Install updates from vendor's website.
envoy - addressed in versions 1.27.6, 1.28.4, 1.29.5, 1.30.2
Istio - addressed in versions 1.20.7, 1.21.3, 1.22.1
OpenShift Service Mesh - addressed in versions 2.4.11, 2.5.5
Istio - addressed in versions 1.20.7, 1.21.3, 1.22.1
OpenShift Service Mesh - addressed in versions 2.4.11, 2.5.5