DEBIAN-CVE-2024-11407

Source
https://security-tracker.debian.org/tracker/DEBIAN-CVE-2024-11407
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-11407.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2024-11407
Upstream
Published
2024-11-26T17:15:22Z
Modified
2025-09-18T05:20:11Z
Summary
[none]
Details

There exists a denial of service through Data corruption in gRPC-C++ - gRPC-C++ servers with transmit zero copy enabled through the channel arg GRPCARGTCPTXZEROCOPY_ENABLED can experience data corruption issues. The data sent by the application may be corrupted before transmission over the network thus leading the receiver to receive an incorrect set of bytes causing RPC requests to fail. We recommend upgrading past commit e9046b2bbebc0cb7f5dc42008f807f6c7e98e791

References

Affected packages

Debian:12 / grpc

Package

Name
grpc
Purl
pkg:deb/debian/grpc?arch=source

Affected ranges

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / grpc

Package

Name
grpc
Purl
pkg:deb/debian/grpc?arch=source

Affected ranges

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / grpc

Package

Name
grpc
Purl
pkg:deb/debian/grpc?arch=source

Affected ranges

Ecosystem specific

{
    "urgency": "not yet assigned"
}