First published: Mon Nov 11 2019(Updated: )
Envoy 1.12.0 allows a remote denial of service because of resource loops, as demonstrated by a single idle TCP connection being able to keep a worker thread in an infinite busy loop when continue_on_listener_filters_timeout is used."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Envoyproxy Envoy | =1.12.0 | |
Istio Istio | >=1.3.0<=1.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18836 is a vulnerability in Envoy 1.12.0 that allows a remote denial of service due to resource loops.
CVE-2019-18836 has a severity rating of 7.5 (high).
Envoy 1.12.0 and Istio versions 1.3.0 to 1.3.3 running on Microsoft Windows Server 2022 are affected by CVE-2019-18836.
CVE-2019-18836 can be exploited by using a single idle TCP connection to keep a worker thread in an infinite busy loop.
Update Envoy to a version later than 1.12.0 and update Istio to a version later than 1.3.3 to mitigate CVE-2019-18836.