CVE-2024-11407Incorrect Calculation in Grpc

Severity
6.9MEDIUMNVD
EPSS
0.0%
top 86.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 26

Description

There exists a denial of service through Data corruption in gRPC-C++ - gRPC-C++ servers with transmit zero copy enabled through the channel arg GRPC_ARG_TCP_TX_ZEROCOPY_ENABLED can experience data corruption issues. The data sent by the application may be corrupted before transmission over the network thus leading the receiver to receive an incorrect set of bytes causing RPC requests to fail. We recommend upgrading past commit e9046b2bbebc0cb7f5dc42008f807f6c7e98e791

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/S:N

Affected Packages5 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-p9rf-64qj-22rw: There exists a denial of service through Data corruption in gRPC-C++ - gRPC-C++ servers with transmit zero copy enabled through the channel arg GRPC_A2024-11-26
OSV
CVE-2024-11407: There exists a denial of service through Data corruption in gRPC-C++ - gRPC-C++ servers with transmit zero copy enabled through the channel arg GRPC_A2024-11-26
CVEList
Denial of Service through Data corruption in gRPC-C++2024-11-26

📋Vendor Advisories

3
Red Hat
grpc: Denial of Service through Data corruption in gRPC-C++2024-11-26
Microsoft
Denial of Service through Data corruption in gRPC-C++2024-11-12
Debian
CVE-2024-11407: grpc - There exists a denial of service through Data corruption in gRPC-C++ - gRPC-C++ ...2024