Uncontrolled Memory Allocation in grpc-node - CVE-2024-37168

 

Uncontrolled Memory Allocation in grpc-node - CVE-2024-37168

Published: October 11, 2024


Vulnerability identifier: #VU98421
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-37168
CWE-ID: CWE-789
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due there are two separate code paths in which memory can be allocated per message in excess of the `grpc.max_receive_message_length` channel option. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

grpc-node
Answer Retrieval for Watson Discovery On Prem
IBM Cloud Pak for Watson AIOps
Voice Gateway
App Connect Enterprise Certified Container
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Maximo Application Suite

How to mitigate CVE-2024-37168

Install updates from vendor's website.

grpc-node - addressed in versions 1.8.22, 1.9.15, 1.10.9
Answer Retrieval for Watson Discovery On Prem - update to 2.18.0
Voice Gateway - addressed in versions 1.0.8.13, 1.0.8.21
App Connect Enterprise Certified Container - addressed in versions 5.0.20, 12.2.0
IBM Cloud Pak for Watson AIOps - update to 4.7.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.0.3
IBM Maximo Application Suite - addressed in versions 8.10.17, 8.11.14, 9.0.3

External References

Related Security Bulletins