CVE-2021-43826: Crash when tunneling TCP over HTTP in Envoy
A flaw was found in envoy. If a downstream source disconnects during upstream connection establishment when tunneling TCP over HTTP, a use-after-free can occur, resulting in a denial of service.
Other sources
Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions of Envoy a crash occurs when configured for :ref:upstream tunneling <envoyv3apifieldextensions.filters.network.tcpproxy.v3.TcpProxy.tunnelingconfig> and the downstream connection disconnects while the the upstream connection or http/2 stream is still being established. There are no workarounds for this issue. Users are advised to upgrade.
Use-after-free when tunneling TCP over HTTP, if downstream disconnects during upstream connection establishment.
— Red Hat
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-43826?
CVE-2021-43826 is a vulnerability in Envoy that can result in a crash when configured for upstream tunneling and the downstream connection disconnects.
How severe is CVE-2021-43826?
CVE-2021-43826 has a severity rating of 7.5 (high).
Which software versions are affected by CVE-2021-43826?
CVE-2021-43826 affects versions up to and excluding 1.18.6, 1.19.3, 1.20.2, and 1.21.1 of Envoy.
How can I fix CVE-2021-43826?
To fix CVE-2021-43826, update your Envoy installation to version 1.18.6, 1.19.3, 1.20.2, or 1.21.1.
Where can I find more information about CVE-2021-43826?
You can find more information about CVE-2021-43826 on the Red Hat Security Advisory page and the official CVE page.