OESA-2023-1682

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2023-1682
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2023-1682.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2023-1682
Upstream
Published
2023-09-22T11:06:01Z
Modified
2025-08-12T05:23:25.665198Z
Summary
grpc security update
Details

gRPC is a modern open source high performance RPC framework that can run in any environment. It can efficiently connect services in and across data centers with pluggable support for load balancing, tracing, health checking and authentication. It is also applicable in last mile of distributed computing to connect devices, mobile applications and browsers to backend services.

Security Fix(es):

Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected. (CVE-2023-4785)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP3 / grpc

Package

Name
grpc
Purl
pkg:rpm/openEuler/grpc&distro=openEuler-20.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.31.0-8.oe1

Ecosystem specific

{
    "src": [
        "grpc-1.31.0-8.oe1.src.rpm"
    ],
    "aarch64": [
        "grpc-1.31.0-8.oe1.aarch64.rpm",
        "grpc-debuginfo-1.31.0-8.oe1.aarch64.rpm",
        "grpc-devel-1.31.0-8.oe1.aarch64.rpm",
        "python3-grpcio-1.31.0-8.oe1.aarch64.rpm",
        "grpc-debugsource-1.31.0-8.oe1.aarch64.rpm"
    ],
    "x86_64": [
        "grpc-debuginfo-1.31.0-8.oe1.x86_64.rpm",
        "grpc-devel-1.31.0-8.oe1.x86_64.rpm",
        "grpc-debugsource-1.31.0-8.oe1.x86_64.rpm",
        "python3-grpcio-1.31.0-8.oe1.x86_64.rpm",
        "grpc-1.31.0-8.oe1.x86_64.rpm"
    ]
}

openEuler:22.03-LTS / grpc

Package

Name
grpc
Purl
pkg:rpm/openEuler/grpc&distro=openEuler-22.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.41.1-5.oe2203sp2

Ecosystem specific

{
    "src": [
        "grpc-1.41.1-5.oe2203.src.rpm",
        "grpc-1.41.1-6.oe2203sp1.src.rpm",
        "grpc-1.41.1-5.oe2203sp2.src.rpm"
    ],
    "aarch64": [
        "grpc-debuginfo-1.41.1-5.oe2203.aarch64.rpm",
        "grpc-debugsource-1.41.1-5.oe2203.aarch64.rpm",
        "python3-grpcio-1.41.1-5.oe2203.aarch64.rpm",
        "grpc-1.41.1-5.oe2203.aarch64.rpm",
        "grpc-devel-1.41.1-5.oe2203.aarch64.rpm",
        "grpc-plugins-1.41.1-5.oe2203.aarch64.rpm",
        "grpc-devel-1.41.1-6.oe2203sp1.aarch64.rpm",
        "grpc-debuginfo-1.41.1-6.oe2203sp1.aarch64.rpm",
        "grpc-plugins-1.41.1-6.oe2203sp1.aarch64.rpm",
        "python3-grpcio-1.41.1-6.oe2203sp1.aarch64.rpm",
        "grpc-debugsource-1.41.1-6.oe2203sp1.aarch64.rpm",
        "grpc-1.41.1-6.oe2203sp1.aarch64.rpm",
        "grpc-1.41.1-5.oe2203sp2.aarch64.rpm",
        "grpc-debugsource-1.41.1-5.oe2203sp2.aarch64.rpm",
        "grpc-devel-1.41.1-5.oe2203sp2.aarch64.rpm",
        "grpc-plugins-1.41.1-5.oe2203sp2.aarch64.rpm",
        "python3-grpcio-1.41.1-5.oe2203sp2.aarch64.rpm",
        "grpc-debuginfo-1.41.1-5.oe2203sp2.aarch64.rpm"
    ],
    "x86_64": [
        "grpc-debuginfo-1.41.1-5.oe2203.x86_64.rpm",
        "grpc-plugins-1.41.1-5.oe2203.x86_64.rpm",
        "grpc-debugsource-1.41.1-5.oe2203.x86_64.rpm",
        "python3-grpcio-1.41.1-5.oe2203.x86_64.rpm",
        "grpc-1.41.1-5.oe2203.x86_64.rpm",
        "grpc-devel-1.41.1-5.oe2203.x86_64.rpm",
        "grpc-1.41.1-6.oe2203sp1.x86_64.rpm",
        "grpc-plugins-1.41.1-6.oe2203sp1.x86_64.rpm",
        "grpc-devel-1.41.1-6.oe2203sp1.x86_64.rpm",
        "grpc-debuginfo-1.41.1-6.oe2203sp1.x86_64.rpm",
        "grpc-debugsource-1.41.1-6.oe2203sp1.x86_64.rpm",
        "python3-grpcio-1.41.1-6.oe2203sp1.x86_64.rpm",
        "grpc-debugsource-1.41.1-5.oe2203sp2.x86_64.rpm",
        "grpc-plugins-1.41.1-5.oe2203sp2.x86_64.rpm",
        "python3-grpcio-1.41.1-5.oe2203sp2.x86_64.rpm",
        "grpc-1.41.1-5.oe2203sp2.x86_64.rpm",
        "grpc-devel-1.41.1-5.oe2203sp2.x86_64.rpm",
        "grpc-debuginfo-1.41.1-5.oe2203sp2.x86_64.rpm"
    ]
}

openEuler:22.03-LTS-SP1 / grpc

Package

Name
grpc
Purl
pkg:rpm/openEuler/grpc&distro=openEuler-22.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.41.1-6.oe2203sp1

Ecosystem specific

{
    "src": [
        "grpc-1.41.1-6.oe2203sp1.src.rpm"
    ],
    "aarch64": [
        "grpc-devel-1.41.1-6.oe2203sp1.aarch64.rpm",
        "grpc-debuginfo-1.41.1-6.oe2203sp1.aarch64.rpm",
        "grpc-plugins-1.41.1-6.oe2203sp1.aarch64.rpm",
        "python3-grpcio-1.41.1-6.oe2203sp1.aarch64.rpm",
        "grpc-debugsource-1.41.1-6.oe2203sp1.aarch64.rpm",
        "grpc-1.41.1-6.oe2203sp1.aarch64.rpm"
    ],
    "x86_64": [
        "grpc-1.41.1-6.oe2203sp1.x86_64.rpm",
        "grpc-plugins-1.41.1-6.oe2203sp1.x86_64.rpm",
        "grpc-devel-1.41.1-6.oe2203sp1.x86_64.rpm",
        "grpc-debuginfo-1.41.1-6.oe2203sp1.x86_64.rpm",
        "grpc-debugsource-1.41.1-6.oe2203sp1.x86_64.rpm",
        "python3-grpcio-1.41.1-6.oe2203sp1.x86_64.rpm"
    ]
}

openEuler:22.03-LTS-SP2 / grpc

Package

Name
grpc
Purl
pkg:rpm/openEuler/grpc&distro=openEuler-22.03-LTS-SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.41.1-5.oe2203sp2

Ecosystem specific

{
    "src": [
        "grpc-1.41.1-5.oe2203sp2.src.rpm"
    ],
    "aarch64": [
        "grpc-1.41.1-5.oe2203sp2.aarch64.rpm",
        "grpc-debugsource-1.41.1-5.oe2203sp2.aarch64.rpm",
        "grpc-devel-1.41.1-5.oe2203sp2.aarch64.rpm",
        "grpc-plugins-1.41.1-5.oe2203sp2.aarch64.rpm",
        "python3-grpcio-1.41.1-5.oe2203sp2.aarch64.rpm",
        "grpc-debuginfo-1.41.1-5.oe2203sp2.aarch64.rpm"
    ],
    "x86_64": [
        "grpc-debugsource-1.41.1-5.oe2203sp2.x86_64.rpm",
        "grpc-plugins-1.41.1-5.oe2203sp2.x86_64.rpm",
        "python3-grpcio-1.41.1-5.oe2203sp2.x86_64.rpm",
        "grpc-1.41.1-5.oe2203sp2.x86_64.rpm",
        "grpc-devel-1.41.1-5.oe2203sp2.x86_64.rpm",
        "grpc-debuginfo-1.41.1-5.oe2203sp2.x86_64.rpm"
    ]
}