Calico Typha hangs during unclean TLS handshake
Published Nov 6, 2023
7.5
HIGHCVSS 3.1
EPSS 0.72%
Description
In certain conditions for Calico Typha (v3.26.2, v3.25.1 and below), and Calico Enterprise Typha (v3.17.1, v3.16.3, v3.15.3 and below), a client TLS handshake can block the Calico Typha server indefinitely, resulting in denial of service. The TLS Handshake() call is performed inside the main server handle for loop without any timeout allowing an unclean TLS handshake to block the main loop indefinitely while other connections will be idle waiting for that handshake to finish.
Affected products
-
Affected
- ≥ 0, ≤ v3.25.1
- ≥ v3.26.0, ≤ v3.26.2
-
Affected
- ≥ 0, ≤ v3.15.3
- ≥ v3.16.0, ≤ v3.16.3
- ≥ v3.17.0, ≤ v3.17.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
- < 18.0.0
- < 3.15.4
- ≥ 3.16.0 · < 3.16.4
- ≥ 3.17.0 · < 3.17.2
- < 3.25.2
- ≥ 3.26.0 · < 3.26.3
-
Affected
- ≥ 0, ≤ v3.25.1
- ≥ v3.26.0, ≤ v3.26.2
-
Affected
- ≥ 0, ≤ v3.15.3
- ≥ v3.16.0, ≤ v3.16.3
- ≥ v3.17.0, ≤ v3.17.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
No Red Hat product state for this CVE.
github.com/projectcalico/calico
Go
Introduced 3.26.0 Fixed 3.26.3github.com/projectcalico/calico
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/projectcalico/calico | 3.26.0 | 3.26.3 |
| Go | github.com/projectcalico/calico | 0 | not fixed |
Remediation
No remediation recorded yet.
References (8)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-2890 Advisory
- https://github.com/advisories/GHSA-5r5h-q934-cccp Advisory
- https://github.com/projectcalico/calico/commit/2ebc1f92ecc39332cf1d55ba676d9101af24982f
- https://github.com/projectcalico/calico/commit/ad8bd001e650ec7742ac30e58247e7eef5956125
- https://github.com/projectcalico/calico/pull/7908 issue-trackingIssue Tracking
- https://github.com/projectcalico/calico/pull/7993 patchIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2023-41378
- https://www.tigera.io/security-bulletins-tta-2023-001/ vendor-advisoryrelease-notesVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-2890 | Advisory | |
| https://github.com/advisories/GHSA-5r5h-q934-cccp | Advisory | |
| https://github.com/projectcalico/calico/commit/2ebc1f92ecc39332cf1d55ba676d9101af24982f | ||
| https://github.com/projectcalico/calico/commit/ad8bd001e650ec7742ac30e58247e7eef5956125 | ||
| https://github.com/projectcalico/calico/pull/7908 | issue-trackingIssue Tracking | |
| https://github.com/projectcalico/calico/pull/7993 | patchIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-41378 | ||
| https://www.tigera.io/security-bulletins-tta-2023-001/ | vendor-advisoryrelease-notesVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub