Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-53456.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-53456
Upstream
Published
2024-11-26T17:15:22Z
Modified
2026-04-01T05:18:03.757427Z
Summary
CVE-2024-11407 affecting package grpc for versions less than 1.62.0-4
Details

There exists a denial of service through Data corruption in gRPC-C++ - gRPC-C++ servers with transmit zero copy enabled through the channel arg GRPCARGTCPTXZEROCOPY_ENABLED can experience data corruption issues. The data sent by the application may be corrupted before transmission over the network thus leading the receiver to receive an incorrect set of bytes causing RPC requests to fail. We recommend upgrading past commit e9046b2bbebc0cb7f5dc42008f807f6c7e98e791

References

Affected packages

Azure Linux:3 / grpc

Package

Name
grpc
Purl
pkg:rpm/azure-linux/grpc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.62.0-4

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-53456.json"