CVE-2024-11407

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-11407
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-11407.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-11407
Related
Published
2024-11-26T17:15:22Z
Modified
2025-01-15T05:06:16.119378Z
Summary
[none]
Details

There exists a denial of service through Data corruption in gRPC-C++ - gRPC-C++ servers with transmit zero copy enabled through the channel arg GRPCARGTCPTXZEROCOPY_ENABLED can experience data corruption issues. The data sent by the application may be corrupted before transmission over the network thus leading the receiver to receive an incorrect set of bytes causing RPC requests to fail. We recommend upgrading past commit e9046b2bbebc0cb7f5dc42008f807f6c7e98e791

References

Affected packages

Debian:11 / grpc

Package

Name
grpc
Purl
pkg:deb/debian/grpc?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.30.2-3
1.30.2-4
1.30.2-4+0.riscv64.1
1.30.2-4+0.riscv64.2
1.44.0-1
1.44.0-2
1.44.0-3
1.50.1-1
1.51.0-1
1.51.1-1
1.51.1-2
1.51.1-3
1.51.1-4
1.51.1-4.1~exp1
1.51.1-4.1
1.51.1-5
1.59.5-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / grpc

Package

Name
grpc
Purl
pkg:deb/debian/grpc?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.51.1-3
1.51.1-4
1.51.1-4.1~exp1
1.51.1-4.1
1.51.1-5
1.59.5-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / grpc

Package

Name
grpc
Purl
pkg:deb/debian/grpc?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.51.1-3
1.51.1-4
1.51.1-4.1~exp1
1.51.1-4.1
1.51.1-5
1.59.5-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/grpc/grpc

Affected ranges

Type
GIT
Repo
https://github.com/grpc/grpc
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.33.1

objective-c-v1.*

objective-c-v1.0.0-pre1
objective-c-v1.0.2

Other

release-0_10_0
release-0_11
release-0_11_0
release-0_11_1
release-0_12
release-0_12_0
release-0_13_0
release-0_13_1
release-0_14
release-0_14_0
release-0_14_1
release-0_15_0
release-0_15_1
release-0_5_0
release-0_6
release-0_6_0
release-0_9_0
release_test

release-0_10_0-objectivec-0.*

release-0_10_0-objectivec-0.6.0

release-0_11_1-objectivec-0.*

release-0_11_1-objectivec-0.11.1

release-0_12_0-objectivec-0.*

release-0_12_0-objectivec-0.12.0

release-0_14_0-objective-c-0.*

release-0_14_0-objective-c-0.14.0

release-0_14_0-objectivec-0.*

release-0_14_0-objectivec-0.14.0

release-0_9_1-objectivec-0.*

release-0_9_1-objectivec-0.5.1

v0.*

v0.15.0

v1.*

v1.0.0
v1.0.0-pre2
v1.0.1
v1.0.1-pre1
v1.1.0
v1.1.0-pre1
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.10.0
v1.10.0-pre1
v1.10.0-pre2
v1.10.1
v1.10.1-pre1
v1.11.0
v1.11.0-pre1
v1.11.0-pre2
v1.12.0
v1.12.0-pre1
v1.12.1
v1.13.0
v1.13.0-pre1
v1.13.0-pre2
v1.13.0-pre3
v1.14.0
v1.14.0-pre1
v1.14.0-pre2
v1.14.1
v1.15.0
v1.15.0-pre1
v1.15.1
v1.16.0
v1.16.0-pre1
v1.16.1
v1.16.1-pre1
v1.17.0
v1.17.0-pre1
v1.17.0-pre2
v1.17.0-pre3
v1.17.1
v1.17.1-pre1
v1.17.2
v1.18.0
v1.18.0-pre1
v1.19.0
v1.19.0-pre1
v1.19.1
v1.2.0
v1.2.0-pre2
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.20.0
v1.20.0-pre1
v1.20.0-pre2
v1.20.0-pre3
v1.20.1
v1.21.0
v1.21.0-pre1
v1.21.1
v1.21.2
v1.21.3
v1.21.3-pre1
v1.21.4
v1.21.4-pre1
v1.22.0
v1.22.0-pre1
v1.23.0
v1.23.0-pre1
v1.24.0
v1.24.0-pre1
v1.24.0-pre2
v1.24.1
v1.24.2
v1.24.3
v1.25.0
v1.25.0-pre1
v1.26.0
v1.26.0-pre1
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.3.6
v1.30.0
v1.30.0-pre1
v1.30.1
v1.30.2
v1.31.0
v1.31.0-pre1
v1.31.0-pre2
v1.31.1
v1.32.0
v1.32.0-pre1
v1.33.0
v1.33.0-pre1
v1.33.0-pre2
v1.33.1
v1.33.2
v1.34.0
v1.34.0-pre1
v1.35.0-pre1
v1.4.0
v1.4.0-pre1
v1.4.1
v1.41.0-pre1
v1.6.0
v1.6.0-pre1
v1.6.1
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.0-pre2
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.9.0
v1.9.0-pre1
v1.9.0-pre2
v1.9.0-pre3
v1.9.1