Bug 2214469 (CVE-2023-32732) - CVE-2023-32732 gRPC: denial of service
Summary: CVE-2023-32732 gRPC: denial of service
Keywords:
Status: NEW
Alias: CVE-2023-32732
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2214472 2214470 2214471
Blocks: 2213811
TreeView+ depends on / blocked
 
Reported: 2023-06-13 06:04 UTC by Avinash Hanwate
Modified: 2023-07-07 08:29 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: ---
Doc Text:
A flaw was found in gRPC, which is vulnerable to a denial of service, caused by a base64 encoding error for "-bin" suffixed headers. By sending a specially crafted request, a remote attacker can cause a termination of the connection between an HTTP2 proxy and a gRPC server, resulting in a denial of service.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Avinash Hanwate 2023-06-13 06:04:30 UTC
gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server: a base64 encoding error for `-bin` suffixed headers will result in a disconnection by the gRPC server, but is typically allowed by HTTP2 proxies. We recommend upgrading beyond the commit in  https://github.com/grpc/grpc/pull/32309 https://www.google.com/url

Comment 1 Avinash Hanwate 2023-06-13 06:05:13 UTC
Created flatbuffers tracking bugs for this issue:

Affects: fedora-all [bug 2214471]


Created grpc tracking bugs for this issue:

Affects: fedora-all [bug 2214470]
Affects: openstack-rdo [bug 2214472]


Note You need to log in before you can comment on or make changes to this bug.