CVE-2021-28682: Integer Overflow
A integer overflow was found in all versions of Envoy up to 1.17.2. If an attacker can craft a packet which specifies a large grpc-timeout, this can potentially cause envoy to incorrectly calculate the timeouts resulting in a denial of service.
Other sources
An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable integer overflow in which a very large grpc-timeout value leads to unexpected timeout calculations.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-28682?
CVE-2021-28682 is a vulnerability discovered in Envoy through 1.71.1 that allows remote exploitation of an integer overflow leading to unexpected timeout calculations.
What is the severity of CVE-2021-28682?
CVE-2021-28682 has a severity rating of 7.5 (High).
Which software versions are affected by CVE-2021-28682?
Envoy versions 1.14.6, 1.15.3, 1.16.2, 1.17.1, and up to, but excluding, 1.17.2 are affected by CVE-2021-28682.
How can I fix CVE-2021-28682?
To fix CVE-2021-28682, upgrade your Envoy software to version 1.17.2 or higher.
Where can I find more information about CVE-2021-28682?
You can find more information about CVE-2021-28682 in the following references: [Link 1](https://blog.envoyproxy.io), [Link 2](https://github.com/envoyproxy/envoy/blob/15e3b9dbcc9aaa9d391fa8033904aad1ea1ae70d/api/envoy/api/v2/cluster.proto#L36), [Link 3](https://github.com/envoyproxy/envoy/releases).