Description
Envoy is a cloud-native, open source edge and service proxy. A crash was observed in `EnvoyQuicServerStream::OnInitialHeadersComplete()` with following call stack. It is a use-after-free caused by QUICHE continuing push request headers after `StopReading()` being called on the stream. As after `StopReading()`, the HCM's `ActiveStream` might have already be destroyed and any up calls from QUICHE could potentially cause use after free.
Remediation
References
Related Vulnerabilities
WordPress Plugin Web Directory Free SQL Injection (1.6.9)
WordPress Other Vulnerability (CVE-2007-3639)
Spring Cloud Gateway Improper Certificate Validation Vulnerability (CVE-2022-22946)
WordPress Plugin MQ ReLinks Multiple Vulnerabilities (1.8)
WordPress Plugin Knews Multilingual Newsletters 'ff' Parameter Cross-Site Scripting (1.1.0)