Hi Kate,
The CVE in the email description (CVE-2024-12176) is different than the CVE from the email body (CVE-2024-13176). I'm assuming the question is about the latter, as it is the one that would apply to the SSL libraries.
BoringSSL is not affected by CVE-2024-13176.
As you point out, there are OpenSSL versions that are affected by CVE-2024-13176. If you choose to build gRPC-C++ with OpenSSL, then you may be affected, depending on your OpenSSL version.
Best,
Matt