CVE-2021-28682

Related Vulnerabilities: CVE-2021-28682  

A flaw was found in envoyproxy/envoy. An attacker, able to craft a packet which specifies a large grpc-timeout, can potentially cause envoy to incorrectly calculate the timeouts resulting in a denial of service. The highest threat from this vulnerability is to system availability.

Description

A flaw was found in envoyproxy/envoy. An attacker, able to craft a packet which specifies a large grpc-timeout, can potentially cause envoy to incorrectly calculate the timeouts resulting in a denial of service. The highest threat from this vulnerability is to system availability.

Additional Information

  • Bugzilla 1942272: CVE-2021-28682 envoyproxy/envoy: integer overflow handling large grpc-timeouts
  • CWE-190: Integer Overflow or Wraparound
  • FAQ: Frequently asked questions about CVE-2021-28682