CVE-2021-32781

Related Vulnerabilities: CVE-2021-32781  

An out-of-bounds memory read vulnerability was found in envoyproxy/envoy. When using one of the following envoy extensions, it is possible to modify and increase the request or response body size of the following: the decompressor, json-transcoder, grpc-web, or other proprietary extensions. This flaw allows an attacker to read invalid memory and cause envoy to crash, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

Description

An out-of-bounds memory read vulnerability was found in envoyproxy/envoy. When using one of the following envoy extensions, it is possible to modify and increase the request or response body size of the following: the decompressor, json-transcoder, grpc-web, or other proprietary extensions. This flaw allows an attacker to read invalid memory and cause envoy to crash, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

Additional Information

  • Bugzilla 1996935: CVE-2021-32781 envoyproxy/envoy: denial of service when using extensions that modify request or response sizes
  • CWE-476: NULL Pointer Dereference
  • FAQ: Frequently asked questions about CVE-2021-32781