v1.28.4
版本发布时间: 2024-06-05 18:36:08
envoyproxy/envoy最新发布版本:v1.31.0(2024-07-20 01:47:50)
repo: Release v1.28.4
Summary of changes:
- CVE-2024-34362: Crash (use-after-free) in EnvoyQuicServerStream
- CVE-2024-34363: Crash due to uncaught nlohmann JSON exception
- CVE-2024-34364: Envoy OOM vector from HTTP async client with unbounded response buffer for mirror response, and other components
- CVE-2024-32974: Crash in EnvoyQuicServerStream::OnInitialHeadersComplete()
- CVE-2024-32975: Crash in QuicheDataReader::PeekVarInt62Length()
- CVE-2024-32976: Endless loop while decompressing Brotli data with extra input
- CVE-2024-23326: Envoy incorrectly accepts HTTP 200 response for entering upgrade mode
Docker images: https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.28.4 Docs: https://www.envoyproxy.io/docs/envoy/v1.28.4/ Release notes: https://www.envoyproxy.io/docs/envoy/v1.28.4/version_history/v1.28/v1.28.4 Full changelog: https://github.com/envoyproxy/envoy/compare/v1.28.3...v1.28.4
Signed-off-by: Boteng Yao boteng@google.com Signed-off-by: Ryan Northey ryan@synca.io
1、 checksums.txt.asc 1.42KB
2、 debs.tar.gz 587.03MB
3、 envoy-1.28.4-linux-aarch_64 62.53MB
4、 envoy-1.28.4-linux-x86_64 66.2MB
5、 envoy-contrib-1.28.4-linux-aarch_64 76.04MB
6、 envoy-contrib-1.28.4-linux-x86_64 88.65MB