Skip to content

Envoy crashes when using an address type that isn’t supported by the OS

High
phlax published GHSA-5m7c-mrwr-pm26 Feb 9, 2024

Package

Envoy Proxy (Envoy)

Affected versions

<1.29.1

Patched versions

1.29.1, 1.28.1, 1.27.3, 1.26.7

Description

Summary

Envoy crashes in Proxy protocol when using an address type that isn’t supported by the OS

Details

Envoy is susceptible to crashing on a host with IPv6 disabled and a listener config with proxy protocol enabled when it receives a request where the client presents its IPv6 address. It is valid for a client to present its IPv6 address to a target server even though the whole chain is connected via IPv4

Impact

Denial of service

Credits

William Dauchy william.dauchy@datadoghq.com

Severity

High
7.5
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE ID

CVE-2024-23325

Weaknesses

Credits