CVE-2022-34038Out-of-bounds Write in Etcd V3

Severity
7.5HIGHNVD
EPSS
0.5%
top 36.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 22

Description

Etcd v3.5.4 allows remote attackers to cause a denial of service via function PageWriter.write in pagewriter.go. NOTE: the vendor's position is that this is not a vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

Gogo.etcd.io/etcd_v3< 3.5.5
NVDetcd/etcd3.5.4

Patches

🔴Vulnerability Details

4
GHSA
etcd denial of service vulnerability2023-08-22
OSV
CVE-2022-34038: ** DISPUTED ** Etcd v32023-08-22
OSV
CVE-2022-34038: Etcd v32023-08-22
CVEList
CVE-2022-34038: Etcd v32023-08-22

📋Vendor Advisories

3
Red Hat
etcd: remote DoS via PageWriter.write2023-08-22
Microsoft
Etcd v3.5.4 allows remote attackers to cause a denial of service via function PageWriter.write in pagewriter.go. NOTE: the vendor's position is that this is not a vulnerability.2023-08-08
Debian
CVE-2022-34038: etcd - Etcd v3.5.4 allows remote attackers to cause a denial of service via function Pa...2022
CVE-2022-34038 — Out-of-bounds Write in Etcd V3 | cvebase