CVE-2024-11407

NameCVE-2024-11407
DescriptionThere exists a denial of service through Data corruption in gRPC-C++ - ...
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1088806

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
grpc (PTS)bullseye1.30.2-3fixed
bookworm1.51.1-3vulnerable
trixie1.51.1-6vulnerable
forky, sid1.51.1-9vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
grpcsourcebullseye(not affected)
grpcsource(unstable)(unfixed)1088806

Notes

[trixie] - grpc <no-dsa> (Minor issue)
[bookworm] - grpc <no-dsa> (Minor issue)
[bullseye] - grpc <not-affected> (vulnerable code introduced later)
Fixed by: https://github.com/grpc/grpc/commit/e9046b2bbebc0cb7f5dc42008f807f6c7e98e791 (v1.68.0-pre1)
Introduced by: https://github.com/grpc/grpc/commit/7655858e931d05ff6208c7e7e87ff0a0a069bef5 (v1.51.0-pre1)

Search for package or bug name: Reporting problems