content/en/news/releases/1.5.x/announcing-1.5.7/index.md
This release fixes the security vulnerability described in our June 30th, 2020 news post.
This release note describes what's different between Istio 1.5.7 and Istio 1.5.6.
{{< relnote >}}
CVE-2020-12603: By sending a specially crafted packet, an attacker could cause Envoy to consume excessive amounts of memory when proxying HTTP/2 requests or responses.
CVE-2020-12605: An attacker could cause Envoy to consume excessive amounts of memory when processing specially crafted HTTP/1.1 packets.
CVE-2020-8663: An attacker could cause Envoy to exhaust file descriptors when accepting too many connections.
CVE-2020-12604: An attacker could cause increased memory usage when processing specially crafted packets.