PT-2020-17337 · Envoy · Envoy

CVE-2020-35471

·

Published

2020-12-15

·

Updated

2024-03-06

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Envoy versions prior to 1.16.1
Description The issue is related to the mishandling of dropped and truncated datagrams, which can cause a segmentation fault when a UDP packet size exceeds 1500.
Recommendations For Envoy versions prior to 1.16.1, update to version 1.16.1 or later to resolve the issue. As a temporary workaround, consider restricting UDP packet sizes to 1500 or less to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BIT-ENVOY-2020-35471
CVE-2020-35471
OPENSUSE-SU-2022:0065-1

Affected Products

Envoy