CVE-2021-28683

Related Vulnerabilities: CVE-2021-28683  

A NULL pointer dereference vulnerability was found envoyproxy/envoy. This flaw allows an attacker to establish a TLS session that sends an invalid TLS alert code, causing a NULL pointer exception to occur that crashes the application, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

Description

A NULL pointer dereference vulnerability was found envoyproxy/envoy. This flaw allows an attacker to establish a TLS session that sends an invalid TLS alert code, causing a NULL pointer exception to occur that crashes the application, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

Additional Information

  • Bugzilla 1942263: CVE-2021-28683 envoyproxy/envoy: NULL pointer dereference in TLS alert code handling
  • CWE-476: NULL Pointer Dereference
  • FAQ: Frequently asked questions about CVE-2021-28683