Skip to content
TrackPodcasts
technologyNov 22, 20207:47pending

Envoy Proxy Fixes Two Zero Day vulnerabilities (UDP Proxy, TCP Proxy)

About this episode

The Envoy Proxy fixed two zero day vulnerabilities, from Envoy groups :

We are announcing the fixes for two zero days that were identified today:

  1. Crash in UDP proxy when datagram size is > 1500. This can happen if either MTU > 1500 or if fragmented datagrams are forwarded and reassembled: https://github.com/envoyproxy/envoy/pull/14122. This issue was already under embargo and a new issue was opened in public GitHub.
  2. Proxy proto downstream address not restored correctly for non-HTTP connectionshttps://github.com/envoyproxy/envoy/pull/14131. This issue was opened publicly recently but the security implications were not clear at the time. This will affect logging and network level RBAC for non-HTTP network connections.

Resources

https://groups.google.com/g/envoy-security-announce/c/aqtBt5VUor0

0:00

0:20 UDP Proxy Crash

2:15 Incorrect Downstream Remote Address

Get every episode summarized

Each time The Backend Engineering Show with Hussein Nasser publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

No transcript yet

This episode has not been transcribed. Request it and it moves to the front of the queue.

Envoy Proxy Fixes Two Zero Day vulnerabilities (UDP Proxy, TCP Proxy)

The Backend Engineering Show with Hussein Nasser

0:00
7:47

More episodes

More from The Backend Engineering Show with Hussein Nasser

View all episodes →