VDB
Sign up
HIGH7.5

GHSA-g9vw-6pvx-7gmw

Envoy: Race condition in Dynamic Forward Proxy leads to use-after-free and segmentation faults

Quick fix

GHSA-g9vw-6pvx-7gmw — github.com/envoyproxy/envoy: upgrade to the fixed version with the command below.

go get github.com/envoyproxy/envoy@v1.35.1

Details

### Summary

A use-after-free (UAF) vulnerability in Envoy's DNS cache causes abnormal process termination. Envoy may reallocate memory when processing a pending DNS resolution, causing list iterator to reference freed memory.

### Details

The vulnerability exists in Envoy's Dynamic Forward Proxy implementation starting from version v1.34.0. The issue occurs when a completion callback for a DNS resolution triggers new DNS resolutions or removes existing pending resolutions. This condition may occur in the following configuration:

1. Dynamic Forwarding Filter is enabled. 2. `envoy.reloadable_features.dfp_cluster_resolves_hosts` runtime flag is enabled. 3. The Host header is modified between the Dynamic Forwarding Filter and Router filters.

### Impact

Denial of service due to abnormal process termination.

### Attack vector(s) Request to Envoy configured as indicated above.

### Patches Users should upgrade to v1.35.1 or v1.34.5.

### Workaround Set the `envoy.reloadable_features.dfp_cluster_resolves_hosts` runtime flag to `false`.

### Detection Abnormal process termination with the `Envoy::Event::DispatcherImpl::runPostCallbacks()` frame in the call stack.

### Credits Rohit Agrawal ([agrawroh](https://github.com/agrawroh)) ([rohit.agrawal@databricks.com](mailto:rohit.agrawal@databricks.com))

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/envoyproxy/envoy
Introduced in: 1.35.0Fixed in: 1.35.1
Fixgo get github.com/envoyproxy/envoy@v1.35.1
Go/github.com/envoyproxy/envoy
Introduced in: 1.34.0Fixed in: 1.34.5
Fixgo get github.com/envoyproxy/envoy@v1.34.5

References