An untrusted remote client may send HTTP/2 requests that write to the heap outside of the request buffers when the upstream is HTTP/1.
Created attachment 1638035 [details] [PATCH 1/3] http: fix heap overflow vulnerability (CVE-2019-18801) 1.12.2-0001-http-fix-heap-overflow-vulnerability-CVE-2019-18801.patch
Created attachment 1638056 [details] [PATCH 1/3] http: fix heap overflow vulnerability (CVE-2019-18801) master-0001-http-fix-heap-overflow-vulnerability-CVE-2019-18801.patch
External References: https://groups.google.com/forum/#!topic/envoy-users/m7z5fGkCzPI https://github.com/envoyproxy/envoy/security/advisories/GHSA-gxvv-x4p2-rppp
This issue has been addressed in the following products: Openshift Service Mesh 1.0 OpenShift Service Mesh 1.0 Via RHSA-2019:4222 https://access.redhat.com/errata/RHSA-2019:4222
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-18801