#VU56107 Use-after-free in envoy


Published: 2021-08-26

Vulnerability identifier: #VU56107

Vulnerability risk: Medium

CVSSv3.1: 5.2 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-32781

CWE-ID: CWE-416

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
envoy
Server applications / IDS/IPS systems, Firewalls and proxy servers

Vendor: Cloud Native Computing Foundation

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a use-after-free error when processing HTTP requests and responses in Envoy. A remote attacker can send a specially crafted HTTP request or response to the application, trigger a use-after-free error and perform a denial of service attack.

Successful exploitation of the vulnerability requires presence of extension that can modify and increase the size of request or response bodies.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

envoy: 1.16.0 - 1.19.0


External links
http://www.envoyproxy.io/docs/envoy/v1.19.0/version_history/version_history
http://github.com/envoyproxy/envoy/security/advisories/GHSA-5vhv-gp9v-42qv


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability