First published: Fri May 20 2022(Updated: )
A flaw was found in Istio. Memory access violation of ill-formed headers sent to Envoy in certain configurations can lead to unexpected memory access, resulting in undefined behavior or crashing.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/servicemesh | <0:2.1.3-1.el8 | 0:2.1.3-1.el8 |
redhat/Istio | <1.12.8 | 1.12.8 |
redhat/Istio | <1.13.5 | 1.13.5 |
redhat/Istio | <1.14.1 | 1.14.1 |
Istio Istio | <1.12.8 | |
Istio Istio | >=1.13.0<1.13.5 | |
Istio Istio | =1.14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31045 is a vulnerability in Istio that allows ill-formed headers sent to Envoy in certain configurations to result in memory access violations and unexpected behavior or crashes.
CVE-2022-31045 affects Istio by allowing ill-formed headers to be sent to Envoy in certain configurations, potentially leading to memory access violations and undefined behavior or crashes.
CVE-2022-31045 has a severity rating of critical.
To fix CVE-2022-31045, users should update their affected versions of Istio to the recommended remediation versions provided by Red Hat.
More information about CVE-2022-31045 can be found on the CVE, NVD, and Istio websites, as well as the Red Hat Bugzilla and Errata pages.