CVE Vulnerabilities

CVE-2024-32976

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Jun 04, 2024 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
root.io logo minimus.io logo echo.ai logo

Envoy is a cloud-native, open source edge and service proxy. Envoyproxy with a Brotli filter can get into an endless loop during decompression of Brotli data with extra input.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

NameVendorStart VersionEnd Version
EnvoyEnvoyproxy1.18.0 (including)1.27.6 (excluding)
EnvoyEnvoyproxy1.28.0 (including)1.28.4 (excluding)
EnvoyEnvoyproxy1.29.0 (including)1.29.5 (excluding)
EnvoyEnvoyproxy1.30.0 (including)1.30.2 (excluding)
Red Hat OpenShift Service Mesh 2.4 for RHEL 8RedHatopenshift-service-mesh/grafana-rhel8:2.4.11-2*
Red Hat OpenShift Service Mesh 2.4 for RHEL 8RedHatopenshift-service-mesh/istio-cni-rhel8:2.4.11-2*
Red Hat OpenShift Service Mesh 2.4 for RHEL 8RedHatopenshift-service-mesh/istio-must-gather-rhel8:2.4.11-3*
Red Hat OpenShift Service Mesh 2.4 for RHEL 8RedHatopenshift-service-mesh/kiali-rhel8:1.65.16-4*
Red Hat OpenShift Service Mesh 2.4 for RHEL 8RedHatopenshift-service-mesh/pilot-rhel8:2.4.11-2*
Red Hat OpenShift Service Mesh 2.4 for RHEL 8RedHatopenshift-service-mesh/proxyv2-rhel8:2.4.11-5*
Red Hat OpenShift Service Mesh 2.4 for RHEL 8RedHatopenshift-service-mesh/ratelimit-rhel8:2.4.11-2*
Red Hat OpenShift Service Mesh 2.5 for RHEL 8RedHatopenshift-service-mesh/grafana-rhel8:2.5.5-3*
Red Hat OpenShift Service Mesh 2.5 for RHEL 8RedHatopenshift-service-mesh/istio-cni-rhel8:2.5.5-4*
Red Hat OpenShift Service Mesh 2.5 for RHEL 8RedHatopenshift-service-mesh/istio-must-gather-rhel8:2.5.5-4*
Red Hat OpenShift Service Mesh 2.5 for RHEL 8RedHatopenshift-service-mesh/kiali-ossmc-rhel8:1.73.14-3*
Red Hat OpenShift Service Mesh 2.5 for RHEL 8RedHatopenshift-service-mesh/kiali-rhel8:1.73.15-3*
Red Hat OpenShift Service Mesh 2.5 for RHEL 8RedHatopenshift-service-mesh/pilot-rhel8:2.5.5-4*
Red Hat OpenShift Service Mesh 2.5 for RHEL 8RedHatopenshift-service-mesh/proxyv2-rhel8:2.5.5-6*
Red Hat OpenShift Service Mesh 2.5 for RHEL 8RedHatopenshift-service-mesh/ratelimit-rhel8:2.5.5-3*

References