CVE-2019-18836: High severity envoy proxy vulnerability
Published Nov 11, 2019
·Updated
Envoy 1.12.0 allows a remote denial of service because of resource loops, as demonstrated by a single idle TCP connection being able to keep a worker thread in an infinite busy loop when continueonlistenerfilterstimeout is used."
Affected Software
2 affected components
Envoyproxy Envoy=1.12.0
Istio Istio>=1.3.0<=1.3.3
Event History
Nov 11, 2019
CVE Published
via MITRE·12:17 AM
Data Sourced
via MITRE·12:17 AM
Description
Frequently Asked Questions
1
What is CVE-2019-18836?
CVE-2019-18836 is a vulnerability in Envoy 1.12.0 that allows a remote denial of service due to resource loops.
2
What is the severity of CVE-2019-18836?
CVE-2019-18836 has a severity rating of 7.5 (high).
3
Which software are affected by CVE-2019-18836?
Envoy 1.12.0 and Istio versions 1.3.0 to 1.3.3 running on Microsoft Windows Server 2022 are affected by CVE-2019-18836.
4
How can CVE-2019-18836 be exploited?
CVE-2019-18836 can be exploited by using a single idle TCP connection to keep a worker thread in an infinite busy loop.
5
How can I fix CVE-2019-18836?
Update Envoy to a version later than 1.12.0 and update Istio to a version later than 1.3.3 to mitigate CVE-2019-18836.