{"id":"CVE-2024-23327","summary":"Crash in proxy protocol when command type of LOCAL in Envoy","details":"Envoy is a high-performance edge/middle/service proxy. When PPv2 is enabled both on a listener and subsequent cluster, the Envoy instance will segfault when attempting to craft the upstream PPv2 header. This occurs when the downstream request has a command type of LOCAL and does not have the protocol block. This issue has been addressed in releases 1.29.1, 1.28.1, 1.27.3, and 1.26.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.","aliases":["BIT-envoy-2024-23327","GHSA-4h5x-x9vh-m29j"],"modified":"2026-08-12T15:15:00.551423Z","published":"2024-02-09T22:41:54.896Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-476"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/23xxx/CVE-2024-23327.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/23xxx/CVE-2024-23327.json"},{"type":"ADVISORY","url":"https://github.com/envoyproxy/envoy/security/advisories/GHSA-4h5x-x9vh-m29j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-23327"},{"type":"FIX","url":"https://github.com/envoyproxy/envoy/commit/63895ea8e3cca9c5d3ab4c5c128ed1369969d54a"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/envoyproxy/envoy","events":[{"introduced":"51964702956d64adcd1df6b8ea132e863fe78e74"},{"fixed":"a0e580408ef4568b0a16c6663b6d8ae0c46aba6a"},{"introduced":"7bba38b743bb3bca22dffb4a21c38ccc155fbef8"},{"fixed":"0fd81ee7ffcd7cfc864094b24dc9b5c3ade89ff2"},{"introduced":"b5ca88acee3453c9459474b8f22215796eff4dde"},{"fixed":"0de8b2b94c75dbe8c2f897058e16d23d959783fa"},{"introduced":"a6d1d66a62b985baed414ba90ad0daebfc074664"},{"fixed":"4fda4d79d06e1bd59e591be3f348223495083648"},{"fixed":"63895ea8e3cca9c5d3ab4c5c128ed1369969d54a"}],"database_specific":{"extracted_events":[{"introduced":"1.26.0"},{"fixed":"1.26.7"},{"introduced":"1.27.0"},{"fixed":"1.27.3"},{"introduced":"1.28.0"},{"fixed":"1.28.1"},{"introduced":"1.29.0"},{"fixed":"1.29.1"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:*"}}],"versions":["v1.29.0","v1.28.0","v1.27.2","v1.26.6","v1.27.1","v1.26.5","v1.27.0","v1.26.4","v1.26.3","v1.26.2","v1.26.1","v1.26.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-23327.json","vanir_signatures_modified":"2026-08-12T15:15:00Z","vanir_signatures":[{"target":{"file":"source/extensions/filters/listener/proxy_protocol/proxy_protocol.cc","function":"Filter::parseBuffer"},"deprecated":false,"digest":{"function_hash":"286811512680485903735342744589460056081","length":3060},"id":"CVE-2024-23327-78c8b622","signature_type":"Function","signature_version":"v1","source":"https://github.com/envoyproxy/envoy/commit/63895ea8e3cca9c5d3ab4c5c128ed1369969d54a"},{"id":"CVE-2024-23327-7f424848","signature_type":"Line","signature_version":"v1","source":"https://github.com/envoyproxy/envoy/commit/63895ea8e3cca9c5d3ab4c5c128ed1369969d54a","target":{"file":"source/extensions/filters/listener/proxy_protocol/proxy_protocol.cc"},"deprecated":false,"digest":{"line_hashes":["80016570650559168734948861518758487464","7726980418944537039522665773032033917","124517097311526218105792622937239282578","102559248476633533035665467834039261240","12991186943772156453422247096583745311","334007753403148273278180061892867810287","260767063508957030680488727075851380283","260387176283359453697210490458957116774","203905052247189264176492778476027185166","280770200438900521359130351191038407324","13248242778338657201764365078624419431","55814014044041630203226279806200476014","272407835860694150955781799448733293698","118152584399675191733394423908381058614","100480408740363530886883644506337972108","24698004173908428480061141208466126212","96705976314550676741566373772215506809","183289610420943466950452525061336027754","141324395016491768902042052538981268059","129521569721628208307496859410291959545"],"threshold":0.9}},{"source":"https://github.com/envoyproxy/envoy/commit/63895ea8e3cca9c5d3ab4c5c128ed1369969d54a","target":{"file":"source/extensions/common/proxy_protocol/proxy_protocol_header.cc","function":"generateV2Header"},"deprecated":false,"digest":{"function_hash":"124884064299760348223722647413180159809","length":1206},"id":"CVE-2024-23327-ac020957","signature_type":"Function","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/envoyproxy/envoy/commit/63895ea8e3cca9c5d3ab4c5c128ed1369969d54a","target":{"file":"source/extensions/common/proxy_protocol/proxy_protocol_header.cc"},"deprecated":false,"digest":{"line_hashes":["105878007581263246315092358702198562589","282122719165119201554788483547474197857","176122346187277616809977244042367783386","112941559382925017819303333849337384653"],"threshold":0.9},"id":"CVE-2024-23327-d0470104","signature_type":"Line"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}