Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions of Envoy a crash occurs when configured for :ref:upstream tunneling <envoy_v3_api_field_extensions.filters.network.tcp_proxy.v3.TcpProxy.tunneling_config>
and the downstream connection disconnects while the the upstream connection or http/2 stream is still being established. There are no workarounds for this issue. Users are advised to upgrade.
{ "vanir_signatures": [ { "signature_version": "v1", "digest": { "length": 808.0, "function_hash": "296559161755360112084384558440136934044" }, "source": "https://github.com/envoyproxy/envoy/commit/ce0ae309057a216aba031aff81c445c90c6ef145", "deprecated": false, "target": { "file": "source/common/tcp_proxy/tcp_proxy.cc", "function": "Filter::onDownstreamEvent" }, "signature_type": "Function", "id": "CVE-2021-43826-0d15ab6b" }, { "signature_version": "v1", "digest": { "length": 711.0, "function_hash": "63191530169222520921233896458439701262" }, "source": "https://github.com/envoyproxy/envoy/commit/ce0ae309057a216aba031aff81c445c90c6ef145", "deprecated": false, "target": { "file": "source/common/tcp_proxy/tcp_proxy.cc", "function": "Filter::onUpstreamEvent" }, "signature_type": "Function", "id": "CVE-2021-43826-541b9b50" }, { "signature_version": "v1", "digest": { "threshold": 0.9, "line_hashes": [ "245673340480709380475607110780385137708", "285494569074532567258474565032572094364", "121492910522987967398570563042373873103", "208903825150298770882316003860954195851" ] }, "source": "https://github.com/envoyproxy/envoy/commit/ce0ae309057a216aba031aff81c445c90c6ef145", "deprecated": false, "target": { "file": "source/common/tcp_proxy/tcp_proxy.h" }, "signature_type": "Line", "id": "CVE-2021-43826-7c5698d5" }, { "signature_version": "v1", "digest": { "threshold": 0.9, "line_hashes": [ "146243477446113422387021212725253250778", "48539946143607539866181123457421037495", "283468910120726656487263215273247794220", "32816829629574534818331468211218975208", "167487698232686579647343259536732486616", "18932793910309592312745692489877318569", "190222441294940987692714025372522320194", "233481120278761949454860284316900076892", "33182693539138785849824461743826464632", "238411867963402661331142337279192022640" ] }, "source": "https://github.com/envoyproxy/envoy/commit/ce0ae309057a216aba031aff81c445c90c6ef145", "deprecated": false, "target": { "file": "source/common/tcp_proxy/tcp_proxy.cc" }, "signature_type": "Line", "id": "CVE-2021-43826-aaaa5efa" }, { "signature_version": "v1", "digest": { "threshold": 0.9, "line_hashes": [ "222375982320279527150068471158201686244", "165738277750233846199418982723160704713", "44051101608002913249948422506083140770" ] }, "source": "https://github.com/envoyproxy/envoy/commit/ce0ae309057a216aba031aff81c445c90c6ef145", "deprecated": false, "target": { "file": "test/integration/tcp_tunneling_integration_test.cc" }, "signature_type": "Line", "id": "CVE-2021-43826-d662927a" } ] }