CVE-2021-29258

Related Vulnerabilities: CVE-2021-29258  

A flaw was found in envoyproxy. An attacker, able to craft an HTTP2 request that specifies an empty metadata map, can crash envoy resulting in a denial of service due to the null reference. The highest threat from this vulnerability is to system availability.

Description

A flaw was found in envoyproxy. An attacker, able to craft an HTTP2 request that specifies an empty metadata map, can crash envoy resulting in a denial of service due to the null reference. The highest threat from this vulnerability is to system availability.

Additional Information

  • Bugzilla 1942280: CVE-2021-29258 envoyproxy/envoy: crash with empty HTTP/2 metadata map
  • CWE-476: NULL Pointer Dereference
  • FAQ: Frequently asked questions about CVE-2021-29258