v1.30.2
版本发布时间: 2024-06-05 21:36:27
envoyproxy/envoy最新发布版本:v1.31.0(2024-07-20 01:47:50)
repo: Release v1.30.2
Summary of changes:
- CVE-2024-34362: Crash (use-after-free) in EnvoyQuicServerStream
- CVE-2024-34363: Crash due to uncaught nlohmann JSON exception
- CVE-2024-34364: Envoy OOM vector from HTTP async client with unbounded response buffer for mirror response, and other components
- CVE-2024-32974: Crash in EnvoyQuicServerStream::OnInitialHeadersComplete()
- CVE-2024-32975: Crash in QuicheDataReader::PeekVarInt62Length()
- CVE-2024-32976: Endless loop while decompressing Brotli data with extra input
- CVE-2024-23326: Envoy incorrectly accepts HTTP 200 response for entering upgrade mode
Docker images: https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.30.2 Docs: https://www.envoyproxy.io/docs/envoy/v1.30.2/ Release notes: https://www.envoyproxy.io/docs/envoy/v1.30.2/version_history/v1.30/v1.30.2 Full changelog: https://github.com/envoyproxy/envoy/compare/v1.30.1...v1.30.2
Signed-off-by: Boteng Yao boteng@google.com Signed-off-by: Ryan Northey ryan@synca.io
1、 checksums.txt.asc 1.42KB
2、 debs.tar.gz 616.74MB
3、 envoy-1.30.2-linux-aarch_64 64.76MB
4、 envoy-1.30.2-linux-x86_64 69.06MB
5、 envoy-contrib-1.30.2-linux-aarch_64 82.22MB
6、 envoy-contrib-1.30.2-linux-x86_64 92.23MB