Envoy is a high-performance edge/middle/service proxy. When PPv2 is enabled both on a listener and subsequent cluster, the Envoy instance will segfault when attempting to craft the upstream PPv2 header. This occurs when the downstream request has a command type of LOCAL and does not have the protocol block. This issue has been addressed in releases 1.29.1, 1.28.1, 1.27.3, and 1.26.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade ecs-service-connect-agent | Mar 6, 2024 | Feb 9, 2024 |
| Amazon_linux_2023 | — | Upgrade ecs-service-connect-agent | Feb 17, 2025 | Feb 9, 2024 |
| Gentoo Linux | — | Upgrade app-admin/consul. | Dec 9, 2024 | Feb 9, 2024 |
| Oracle_linux | — | Upgrade etcdUpgrade olcne-utilsUpgrade olcne-istio-chartUpgrade istioUpgrade kubectlUpgrade olcneUpgrade olcne-oci-ccm-chartUpgrade cri-toolsUpgrade olcne-api-serverUpgrade olcne-kubevirt-chartUpgrade olcne-calico-chartUpgrade cri-oUpgrade olcne-nginxUpgrade olcnectlUpgrade olcne-agentUpgrade olcne-prometheus-chartUpgrade olcne-grafana-chartUpgrade olcne-olm-chartUpgrade kubeletUpgrade kubeadmUpgrade olcne-gluster-chartUpgrade olcne-rook-chartUpgrade olcne-multus-chartUpgrade istio-istioctlUpgrade kubernetesUpgrade olcne-metallb-chart | Apr 17, 2024 | Feb 9, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub