CVE Vulnerabilities

CVE-2024-32976

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Jun 04, 2024 | Modified: Jun 12, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu

Envoy is a cloud-native, open source edge and service proxy. Envoyproxy with a Brotli filter can get into an endless loop during decompression of Brotli data with extra input.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Envoy Envoyproxy 1.18.0 (including) 1.27.6 (excluding)
Envoy Envoyproxy 1.28.0 (including) 1.28.4 (excluding)
Envoy Envoyproxy 1.29.0 (including) 1.29.5 (excluding)
Envoy Envoyproxy 1.30.0 (including) 1.30.2 (excluding)

References