🐛 Remote code execution in the Elixir gRPC package

Affected resources
gRPC Erlang versions prior to 1.0.0, starting from version 0.4.0 inclusive.

:spiral_notepad: Peter Ullrich has discovered a vulnerability in the gRPC protocol implementation for Elixir that can cause the entire BEAM node to collapse by exhausting the atom table and, when a decoded term flows to a call site that invokes it, achieve remote code execution on the server.

:eight_spoked_asterisk: Fix: It is recommended to upgrade to version 1.0.0.

Targeted at:

  • People working with Elixir and Erlang/OTP.

  • Affected framework or library: the gRPC Erlang package, which is the gRPC protocol implementation for Elixir.

It has a Critical severity rating, so an urgent update is recommended.

Regards developers,
Sergio Turpín

1 Like