Upstream information

CVE-2026-73549 at MITRE

Description

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's Utility::copyInternetAddressAndPort and QUIC client-address paths reconstruct scoped IPv6 addresses through addressAsString and Ipv6Instance. The string includes a percent scope identifier that inet_pton cannot parse, causing an exception or abort. Kernel-provided scoped IPv6 destinations in ORIGINAL_DST transparent-proxy deployments, and affected QUIC connection paths, can therefore terminate the process. The relevant scope boundary is that the HTTP use_http_header override rejects scoped addresses earlier; the advisory's crash path requires a kernel-provided original destination or the affected QUIC path. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having moderate severity.

No SUSE Bugzilla entries cross referenced.

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
openSUSE Tumbleweed
  • istioctl >= 1.30.4-1.1
  • istioctl-bash-completion >= 1.30.4-1.1
  • istioctl-zsh-completion >= 1.30.4-1.1
Patchnames:
openSUSE-Tumbleweed-2026-11630


SUSE Timeline for this CVE

CVE page created: Sat Aug 29 13:13:25 2026
CVE page last modified: Tue Sep 22 11:44:09 2026