Skip to content

Connection flood exhausts memory and file descriptors

High
mattklein123 published GHSA-v8q7-fq78-4997 Jun 30, 2020

Package

No package listed

Affected versions

1.14.2, 1.13.2, 1.12.4 or older

Patched versions

1.14.3, 1.13.3, 1.12.5

Description

Vulnerability type

Uncontrolled Resource Consumption

Attack type

Remote

Impact

Denial-of-service, Resource consumption (memory)

Discoverer(s)/Credits

Piotr Sikora (Google LLC)

Description

Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may exhaust file descriptors and/or memory when accepting too many connections. Large numbers of connections may be opened against Envoy, with no data sent, causing Envoy to eventually run out of file descriptors and crash.

Severity

High

CVE ID

CVE-2020-8663

Weaknesses

No CWEs