Envoy Proxy Use After Free Vulnerability - CVE-2021-43826 - Vulnerability Database

Envoy Proxy Use After Free Vulnerability - CVE-2021-43826

High
Reference: CVE-2021-43826
Title: Envoy Proxy Use After Free Vulnerability
Overview:

Envoy is an open source edge and service proxy designed for cloud-native applications. In affected versions of Envoy a crash occurs when configured for :ref:upstream tunneling ltenvoy_v3_api_field_extensions.filters.network.tcp_proxy.v3.TcpProxy.tunneling_configgt and the downstream connection disconnects while the the upstream connection or http/2 stream is still being established. There are no workarounds for this issue. Users are advised to upgrade.