Bug 2239017 (CVE-2023-4785) - CVE-2023-4785 gRPC: file descriptor exhaustion leads to denial of service
Summary: CVE-2023-4785 gRPC: file descriptor exhaustion leads to denial of service
Keywords:
Status: NEW
Alias: CVE-2023-4785
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2239018 2239187 2239188
Blocks: 2238998
TreeView+ depends on / blocked
 
Reported: 2023-09-14 19:38 UTC by Chess Hazlett
Modified: 2023-09-26 18:59 UTC (History)
46 users (show)

Fixed In Version: grpc 1.53.2, grpc 1.54.3, grpc 1.55.3, grpc 1.56.2
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in gRPC. Lack of error handling in the TCP server in Google's gRPC, starting in version 1.23 on POSIX-compatible platforms (for example, Linux), allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++, Python, and Ruby are affected, but gRPC Java and Go are NOT affected.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Chess Hazlett 2023-09-14 19:38:35 UTC
Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.

Comment 3 Guilherme de Almeida Suckevicz 2023-09-15 19:15:13 UTC
Created etcd tracking bugs for this issue:

Affects: openstack-rdo [bug 2239188]


Created golang-google-grpc tracking bugs for this issue:

Affects: fedora-all [bug 2239187]


Note You need to log in before you can comment on or make changes to this bug.