{"document":{"aggregate_severity":{"namespace":"https://www.suse.com/support/security/rating/","text":"moderate"},"category":"csaf_vex","csaf_version":"2.0","distribution":{"text":"Copyright 2024 SUSE LLC. All rights reserved.","tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en","notes":[{"category":"summary","text":"SUSE CVE-2022-29224","title":"Title"},{"category":"description","text":"Envoy is a cloud-native high-performance proxy. Versions of envoy prior to 1.22.1 are subject to a segmentation fault in the GrpcHealthCheckerImpl. Envoy can perform various types of upstream health checking. One of them uses gRPC. Envoy also has a feature which can \"hold\" (prevent removal) upstream hosts obtained via service discovery until configured active health checking fails. If an attacker controls an upstream host and also controls service discovery of that host (via DNS, the EDS API, etc.), an attacker can crash Envoy by forcing removal of the host from service discovery, and then failing the gRPC health check request. This will crash Envoy via a null pointer dereference. Users are advised to upgrade to resolve this vulnerability. Users unable to upgrade may disable gRPC health checking and/or replace it with a different health checking type as a mitigation.","title":"Description of the CVE"},{"category":"legal_disclaimer","text":"CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).","title":"Terms of use"}],"publisher":{"category":"vendor","contact_details":"https://www.suse.com/support/security/contact/","name":"SUSE Product Security Team","namespace":"https://www.suse.com/"},"references":[{"category":"external","summary":"CVE-2022-29224","url":"https://www.suse.com/security/cve/CVE-2022-29224"},{"category":"external","summary":"SUSE Security Ratings","url":"https://www.suse.com/support/security/rating/"},{"category":"external","summary":"SUSE Bug 1200401 for CVE-2022-29224","url":"https://bugzilla.suse.com/1200401"}],"title":"SUSE CVE CVE-2022-29224","tracking":{"current_release_date":"2025-12-19T01:49:44Z","generator":{"date":"2024-05-29T10:16:12Z","engine":{"name":"cve-database.git:bin/generate-csaf-vex.pl","version":"1"}},"id":"CVE-2022-29224","initial_release_date":"2024-05-29T10:16:12Z","revision_history":[{"date":"2024-05-29T10:16:12Z","number":"2","summary":"Current version"},{"date":"2024-06-04T12:42:58Z","number":"3","summary":"Current version"},{"date":"2025-01-01T03:05:35Z","number":"4","summary":"Current version"},{"date":"2025-02-14T07:46:18Z","number":"5","summary":"Current version"},{"date":"2025-02-16T07:28:34Z","number":"6","summary":"Current version"},{"date":"2025-12-17T01:36:35Z","number":"7","summary":"description changed"},{"date":"2025-12-19T01:49:44Z","number":"8","summary":"description changed"}],"status":"interim","version":"8"}}}