Envoy is an open source edge and service proxy, designed for cloud-native applications. When a cluster is deleted via Cluster Discovery Service (CDS) all idle connections established to endpoints in that cluster are disconnected. A recursion was introduced in the procedure of disconnecting idle connections that can lead to stack exhaustion and abnormal process termination when a cluster has a large number of idle connections. This infinite recursion causes Envoy to crash. Users are advised to upgrade.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2022-02-22T22:20:13

Updated: 2024-08-03T03:43:46.828Z

Reserved: 2022-01-19T00:00:00

Link: CVE-2022-23606

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-02-22T23:15:11.337

Modified: 2022-03-02T14:37:33.870

Link: CVE-2022-23606

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-02-22T07:00:00Z

Links: CVE-2022-23606 - Bugzilla