Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Cur 1.27 #25

Merged
merged 8 commits into from
Apr 27, 2024
Merged

Cur 1.27 #25

merged 8 commits into from
Apr 27, 2024

Conversation

nfuden
Copy link
Collaborator

@nfuden nfuden commented Apr 27, 2024

No description provided.

phlax and others added 8 commits April 10, 2024 14:19
Signed-off-by: Ryan Northey <ryan@synca.io>
Signed-off-by: Ryan Northey <ryan@synca.io>
…33303)

Signed-off-by: Christoph Pakulski <paker8848@gmail.com>
Signed-off-by: Ryan Northey <ryan@synca.io>
* tls: fix RELEASE_ASSERT when using `auto_sni`

If the `:authority` was longer than 255 characters, Envoy would
RELEASE_ASSERT when creating an upstream TLS connection when
`auto_sni` (https://www.envoyproxy.io/docs/envoy/v1.30.0/api-v3/config/core/v3/protocol.proto.html#config-core-v3-upstreamhttpprotocoloptions)
was used.

Signed-off-by: Greg Greenway <ggreenway@apple.com>
Signed-off-by: Ryan Northey <ryan@synca.io>
**Summary of changes**:

* Fix for potential TLS/SNI (`auto_sni`) crash [CVE pending](GHSA-3mh5-6q8v-25wj).

**Docker images**:
    https://hub.docker.com/r/envoyproxy/envoy/tags?page=1&name=v1.27.5
**Docs**:
    https://www.envoyproxy.io/docs/envoy/v1.27.5/
**Release notes**:
    https://www.envoyproxy.io/docs/envoy/v1.27.5/version_history/v1.27/v1.27.5
**Full changelog**:
    envoyproxy/envoy@v1.27.4...v1.27.5

Signed-off-by: Ryan Northey <ryan@synca.io>
Signed-off-by: Ryan Northey <ryan@synca.io>
@nfuden nfuden merged commit defe1b8 into release/v1.27-backportedfork Apr 27, 2024
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
4 participants