Restart snowflake bridges for haproxy CVE-2023-0836
The vulnerability has to do with FastCGI, which we don't use.
https://security-tracker.debian.org/tracker/DSA-5388-1
https://lists.debian.org/debian-security-announce/2023/msg00078.html
An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when encoding the FCGI_BEGIN_REQUEST record. Sensitive data may be disclosed to configured FastCGI backends in an unexpected way.
https://ubuntu.com/security/notices/USN-5994-1
It was discovered that HAProxy incorrectly initialized certain connection buffers. A remote attacker could possibly use this issue to obtain sensitive information.
-
snowflake-01 -
snowflake-02
/cc @linus
Past haproxy upgrade issue: #40253 (closed).