An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable NULL pointer dereference and crash in TLS when an unknown TLS alert code is received.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://github.com/envoyproxy/envoy/releases | third party advisory |
https://blog.envoyproxy.io | vendor advisory |
https://github.com/envoyproxy/envoy/security/advisories/GHSA-r22g-5f3x-xjgg | third party advisory not applicable |
https://github.com/envoyproxy/envoy/security/advisories/GHSA-xw4q-6pj2-5gfg | third party advisory |