跳转到帖子

Red Hat: CVE-2023-1428: gRPC: Reachable Assertion (Multiple Advisories)

recommended_posts

发布于
  • Members

Red Hat: CVE-2023-1428: gRPC: Reachable Assertion (Multiple Advisories)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
06/09/2023
Created
02/11/2025
Added
02/10/2025
Modified
02/10/2025

Description

There exists an vulnerability causing an abort() to be called in gRPC.  The following headers cause gRPC's C++ implementation to abort() when called via http2: te: x (x != trailers) :scheme: x (x != http, https) grpclb_client_stats: x (x == anything) On top of sending one of those headers, a later header must be sent that gets the total header size past 8KB. We recommend upgrading past git commit 2485fa94bd8a723e5c977d55a3ce10b301b437f8 or v1.53 and above.

Solution(s)

  • redhat-upgrade-rhc-worker-playbook
  • redhat-upgrade-rhc-worker-playbook-debuginfo

References

  • CVE-2023-1428
  • RHSA-2024:10761
  • 查看数 698
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…