UBUNTU-CVE-2024-11407

Source
https://ubuntu.com/security/CVE-2024-11407
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-11407.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2024-11407
Related
Published
2024-11-26T17:15:00Z
Modified
2025-01-13T10:24:48Z
Summary
[none]
Details

There exists a denial of service through Data corruption in gRPC-C++ - gRPC-C++ servers with transmit zero copy enabled through the channel arg GRPCARGTCPTXZEROCOPY_ENABLED can experience data corruption issues. The data sent by the application may be corrupted before transmission over the network thus leading the receiver to receive an incorrect set of bytes causing RPC requests to fail. We recommend upgrading past commit e9046b2bbebc0cb7f5dc42008f807f6c7e98e791

References

Affected packages

Ubuntu:Pro:16.04:LTS / grpc

Package

Name
grpc
Purl
pkg:deb/ubuntu/grpc@0.11.1-1?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.10.2-1
0.11.1-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / grpc

Package

Name
grpc
Purl
pkg:deb/ubuntu/grpc@1.3.2-1.1~build1?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.3.2-1
1.3.2-1ubuntu1
1.3.2-1.1~build1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / grpc

Package

Name
grpc
Purl
pkg:deb/ubuntu/grpc@1.16.1-1ubuntu5?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.16.1-1
1.16.1-1ubuntu1
1.16.1-1ubuntu3
1.16.1-1ubuntu4
1.16.1-1ubuntu5

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / grpc

Package

Name
grpc
Purl
pkg:deb/ubuntu/grpc@1.30.2-3build6?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.30.2-3
1.30.2-3build1
1.30.2-3build3
1.30.2-3build5
1.30.2-3build6

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / grpc

Package

Name
grpc
Purl
pkg:deb/ubuntu/grpc@1.51.1-4.1ubuntu1?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.51.1-4.1build5
1.51.1-4.1build6
1.51.1-4.1build8
1.51.1-4.1ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / grpc

Package

Name
grpc
Purl
pkg:deb/ubuntu/grpc@1.51.1-4.1build5?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.51.1-3build3
1.51.1-3build4
1.51.1-4
1.51.1-4build1
1.51.1-4build2
1.51.1-4.1build3
1.51.1-4.1build4
1.51.1-4.1build5

Ecosystem specific

{
    "ubuntu_priority": "medium"
}