Severity
6.5MEDIUMNVD
EPSS
0.1%
top 70.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 5
Latest updateFeb 7

Description

In etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index greater then the number of entries in the ReadAll method in wal/wal.go. This could cause issues when WAL entries are being read during consensus as an arbitrary etcd consensus participant could go down from a runtime panic when reading the entry.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages6 packages

NVDetcd/etcd3.4.03.4.10+1
CVEListV5etcd-io/etcd< 3.3.23+1
Gogo.etcd.io/etcd< 0.5.0-alpha.5.0.20200423152442-f4b650b51dc4
Gogo.etcd.io/etcd_v33.4.03.4.10+1
Debianetcd/etcd< 3.3.25+dfsg-5+3

Also affects: Fedora 32

🔴Vulnerability Details

8
OSV
Panic due to malformed WALs in go.etcd.io/etcd2023-02-07
GHSA
etcd's WAL `ReadAll` method vulnerable to an entry with large index causing panic2022-10-06
OSV
etcd's WAL `ReadAll` method vulnerable to an entry with large index causing panic2022-10-06
OSV
etcd vulnerabilities2022-09-22
OSV
etcd vulnerabilities2022-09-22

📋Vendor Advisories

5
Ubuntu
etcd vulnerabilities2022-09-22
Ubuntu
etcd vulnerabilities2022-09-22
Microsoft
Improper Input Validation in etcd2020-08-11
Red Hat
etcd: DoS in wal/wal.go2020-08-06
Debian
CVE-2020-15112: etcd - In etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index...2020

💬Community

2
Bugzilla
CVE-2020-15112 etcd: DoS in wal/wal.go [fedora-all]2020-08-14
Bugzilla
CVE-2020-15112 etcd: DoS in wal/wal.go2020-08-14
CVE-2020-15112 — Improper Input Validation in Etcd | cvebase