Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookkeeping structures upon receiving `RST_STREAM` immediately followed by the `GOAWAY` frames from an upstream server. In nghttp2, cleanup of pending requests due to receipt of the `GOAWAY` frame skips de-allocation of the bookkeeping structure and pending compressed header. The error return [code path] is taken if connection is already marked for not sending more requests due to `GOAWAY` frame. The clean-up code is right after the return statement, causing memory leak. Denial of service through memory exhaustion. This vulnerability was patched in versions(s) 1.26.3, 1.25.8, 1.24.9, 1.23.11.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-nghttp2 | Aug 22, 2024 | Jul 13, 2023 | |
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-ecs-service-connect-agentamazon-linux-ami-2-upgrade-libnghttp2amazon-linux-ami-2-upgrade-libnghttp2-develamazon-linux-ami-2-upgrade-nghttp2amazon-linux-ami-2-upgrade-nghttp2-debuginfo | Aug 9, 2023 | Jul 13, 2023 | |
| Amazon_linux | — | amazon-linux-upgrade-nghttp2 | Aug 9, 2023 | Jul 13, 2023 |
| Amazon_linux_2023 | amazon-linux-2023-upgrade-ecs-service-connect-agentamazon-linux-2023-upgrade-libnghttp2amazon-linux-2023-upgrade-libnghttp2-debuginfoamazon-linux-2023-upgrade-libnghttp2-develamazon-linux-2023-upgrade-nghttp2amazon-linux-2023-upgrade-nghttp2-debuginfoamazon-linux-2023-upgrade-nghttp2-debugsource | Feb 17, 2025 | Jul 13, 2023 | |
| Huawei Euleros 2_0_sp10 | huawei-euleros-2_0_sp10-upgrade-libnghttp2 | Jan 10, 2024 | Jul 13, 2023 | |
| Huawei Euleros 2_0_sp11 | huawei-euleros-2_0_sp11-upgrade-libnghttp2 | Jan 10, 2024 | Jul 13, 2023 | |
| Huawei Euleros 2_0_sp9 | huawei-euleros-2_0_sp9-upgrade-libnghttp2 | Jan 10, 2024 | Jul 13, 2023 | |
| Suse | — | suse-upgrade-libnghttp2-14suse-upgrade-libnghttp2-14-32bitsuse-upgrade-libnghttp2-develsuse-upgrade-libnghttp2_asio-develsuse-upgrade-libnghttp2_asio1suse-upgrade-libnghttp2_asio1-32bitsuse-upgrade-nghttp2suse-upgrade-python3-nghttp2 | Sep 28, 2023 | Jul 13, 2023 |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Jul 13, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub