VDB
Sign up
MEDIUM6.5

GHSA-cf3q-gqg7-3fm9

Envoy crashes when HTTP ext_proc processes local replies

Quick fix

GHSA-cf3q-gqg7-3fm9 — github.com/envoyproxy/envoy: upgrade to the fixed version with the command below.

go get github.com/envoyproxy/envoy@v1.30.10

Details

### Summary Envoy's ext_proc HTTP filter is at risk of crashing if a local reply is sent to the external server due to the filter's life time issue. A known situation is the fail of a websocket handshake will trigger a local reply leading to the crash of Envoy.

### PoC If both websocket and ext_proc are enabled, a failed handshake will trigger a local reply, thus ext_proc will crash.

### Mitigation 1. Disable websocket traffic 2. Change the websocket response from backend to always return `101 Switch protocol` based on RFC. 3. Apply the patch and the ext_proc filter will not send the local reply that is generated by Envoy to the ext_proc server for processing. 4. Apply the patch that the router will cancel the upstream requests when sending a local reply.

### Impact Denial of service

### Reporter Vasilios Syrakis Fernando Cainelli

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/envoyproxy/envoy
Introduced in: 0Fixed in: 1.30.10
Fixgo get github.com/envoyproxy/envoy@v1.30.10
Go/github.com/envoyproxy/envoy
Introduced in: 1.31.0Fixed in: 1.31.6
Fixgo get github.com/envoyproxy/envoy@v1.31.6
Go/github.com/envoyproxy/envoy
Introduced in: 1.32.0Fixed in: 1.32.4
Fixgo get github.com/envoyproxy/envoy@v1.32.4
Go/github.com/envoyproxy/envoy
Introduced in: 1.33.0Fixed in: 1.33.1
Fixgo get github.com/envoyproxy/envoy@v1.33.1

References