CVE-2024-32975

Severity CVSS v4.0:
Pending analysis
Type:
CWE-191 Integer Underflow (Wrap or Wraparound)
Publication date:
04/06/2024
Last modified:
12/06/2024

Description

Envoy is a cloud-native, open source edge and service proxy. There is a crash at `QuicheDataReader::PeekVarInt62Length()`. It is caused by integer underflow in the `QuicStreamSequencerBuffer::PeekRegion()` implementation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:* 1.27.6 (excluding)
cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:* 1.28.0 (including) 1.28.4 (excluding)
cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:* 1.29.0 (including) 1.29.5 (excluding)
cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:* 1.30.0 (including) 1.30.2 (excluding)