Back to bug 2230890

Who When What Removed Added
Mauro Matteo Cascella 2023-08-10 08:35:40 UTC Blocks 2230893
Avinash Hanwate 2023-08-11 04:41:52 UTC Alias TRIAGE-CVE-2023-33953 CVE-2023-33953
Fixed In Version gRPC 1.53.2, gRPC 1.54.3, gRPC 1.55.2, gRPC 1.56.2, gRPC 1.57
Avinash Hanwate 2023-08-11 04:55:29 UTC Doc Text A flaw was found in the gRPC lib. This vulnerability allows hpack table accounting errors that could lead to unwanted disconnects between clients and servers in exceptional cases which leads to Unbounded memory buffering in the HPACK parser and Unbounded CPU consumption in the HPACK parser.
Summary TRIAGE-CVE-2023-33953 gRPC: hpack table accounting errors can lead to denial of service CVE-2023-33953 gRPC: hpack table accounting errors can lead to denial of service
Avinash Hanwate 2023-08-11 04:56:38 UTC Depends On 2231221, 2231222, 2231220
RaTasha Tillery-Smith 2023-08-11 12:18:29 UTC Doc Text A flaw was found in the gRPC lib. This vulnerability allows hpack table accounting errors that could lead to unwanted disconnects between clients and servers in exceptional cases which leads to Unbounded memory buffering in the HPACK parser and Unbounded CPU consumption in the HPACK parser. A flaw was found in the gRPC lib. This vulnerability allows hpack table accounting errors that could lead to unwanted disconnects between clients and servers in exceptional cases. This issue leads to Unbounded memory buffering in the HPACK parser and Unbounded CPU consumption in the HPACK parser.
Ben Beasley 2023-08-11 14:40:35 UTC CC code

Back to bug 2230890