Skip to content

Empty Frames Flood

High
htuch published GHSA-rj7v-w93w-4cw8 Nov 8, 2019

Package

No package listed

Affected versions

<= 1.11.0

Patched versions

1.11.1

Description

The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSH_PROMISE. The peer spends time processing each frame disproportionate to attack bandwidth. This can consume excess CPU, potentially leading to a denial of service.

See https://groups.google.com/g/envoy-announce/c/ZLchtraPYVk, https://www.envoyproxy.io/docs/envoy/v1.11.1/intro/version_history and https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md.

Severity

High

CVE ID

CVE-2019-9518

Weaknesses

No CWEs