Описание
HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.
A flaw was found in HAProxy. A malicious FastCGI (Fast Common Gateway Interface) backend can exploit an integer overflow vulnerability in the fcgi_conn structure's drl field. This occurs when specific contentLength and paddingLength values cause the drl field to wrap to zero, leading to incorrect record consumption. This desynchronizes the FCGI framing parser, potentially resulting in response smuggling, request routing errors, or memory safety issues.
Отчет
Conditions for Exploitation: Successful exploitation requires a specific configuration where HAProxy is actively utilizing a FastCGI backend. Crucially, an attacker must already have control over this backend server to supply the maliciously crafted responses. This requirement significantly restricts the attack vector, as it relies on an unlikely configuration or an already compromised backend, rather than a typical remote attack initiated by a client against a default frontend server. Impact Limitations: Although the vulnerability can cause the FastCGI framing parser to desynchronize—potentially leading to response smuggling, request routing errors, or memory safety issues—the threat is contained entirely to environments that process traffic from untrusted or compromised backend servers.
Меры по смягчению последствий
To mitigate this issue, restrict access to HAProxy instances that utilize FastCGI to trusted FastCGI backends only. If FastCGI is not required, consider disabling its use in HAProxy configurations to eliminate the attack vector. Ensure that all FastCGI backends are secured and not susceptible to compromise. If the HAProxy service is reloaded or restarted after configuration changes, ensure proper validation of the new configuration.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Ceph Storage 5 | rhceph/rhceph-haproxy-rhel8 | Affected | ||
| Red Hat Ceph Storage 6 | rhceph/rhceph-haproxy-rhel9 | Affected | ||
| Red Hat Ceph Storage 7 | rhceph/rhceph-haproxy-rhel9 | Affected | ||
| Red Hat Ceph Storage 8 | rhceph/rhceph-haproxy-rhel9 | Affected | ||
| Red Hat Ceph Storage 9 | rhceph-ci/haproxy | Affected | ||
| Red Hat Ceph Storage 9 | rhceph/rhceph-haproxy-rhel10 | Affected | ||
| Red Hat Ceph Storage 9 | rhceph/rhceph-haproxy-rhel9 | Affected | ||
| Red Hat Enterprise Linux 10 | haproxy | Affected | ||
| Red Hat Enterprise Linux 7 | haproxy | Out of support scope | ||
| Red Hat Enterprise Linux 8 | haproxy | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.
HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.
HAProxy - Integer Overflow in FCGI Demux Record Length Field
HAProxy through 3.4.0, fixed in commit 5985276, contains an integer ov ...
HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.
EPSS
7.5 High
CVSS3