Vulnerability Database
Blog
FAQ
Docs
SUSE-SU-2024:4400-1
See a problem?
Please try reporting it
to the source
first.
Source
https://www.suse.com/support/update/announcement/2024/suse-su-20244400-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:4400-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2024:4400-1
Related
CVE-2024-11407
CVE-2024-7246
Published
2024-12-20T15:27:37Z
Modified
2024-12-20T15:27:37Z
Summary
Security update for grpc
Details
This update for grpc fixes the following issues:
CVE-2024-7246: HPACK table poisoning by gRPC clients communicating with a HTTP/2 proxy. (bsc#1228919)
CVE-2024-11407: data corruption on servers with transmit zero copy enabled. (bsc#1233821)
References
https://www.suse.com/support/update/announcement/2024/suse-su-20244400-1/
https://bugzilla.suse.com/1228919
https://bugzilla.suse.com/1233821
https://www.suse.com/security/cve/CVE-2024-11407
https://www.suse.com/security/cve/CVE-2024-7246
Affected packages
SUSE:Linux Enterprise Module for Public Cloud 15 SP4
/
grpc
Package
Name
grpc
Purl
pkg:rpm/suse/grpc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP4
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1.60.0-150400.8.8.1
Ecosystem specific
{ "binaries": [ {} ] }
SUSE-SU-2024:4400-1 - OSV