CVE-2023-33953 — Memory Allocation with Excessive Size Value in Google Grpc
Severity
7.5HIGHNVD
EPSS
0.1%
top 69.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 9
Latest updateJan 15
Description
gRPC contains a vulnerability that allows hpack table accounting errors could lead to unwanted disconnects between clients and servers in exceptional cases/ Three vectors were found that allow the following DOS attacks:
- Unbounded memory buffering in the HPACK parser
- Unbounded CPU consumption in the HPACK parser
The unbounded CPU consumption is down to a copy that occurred per-input-block in the parser, and because that could be unbounded due to the memory copy bug we end up with an O(n^2) …
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6
Affected Packages3 packages
🔴Vulnerability Details
4OSV▶
CVE-2023-33953: gRPC contains a vulnerability that allows hpack table accounting errors could lead to unwanted disconnects between clients and servers in exceptional↗2023-08-09
📋Vendor Advisories
4Oracle
▶
Debian▶
CVE-2023-33953: grpc - gRPC contains a vulnerability that allows hpack table accounting errors could le...↗2023