In etcd before versions 3.3.23 and 3.4.10, a large slice causes panic in decodeRecord method. The size of a record is stored in the length field of a WAL file and no additional validation is done on this data. Therefore, it is possible to forge an extremely large frame size that can unintentionally panic at the expense of any RAFT participant trying to decode the WAL.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade etcdUpgrade etcd-debuginfo | Jun 1, 2021 | Aug 5, 2020 |
| Debian | — | Upgrade etcd | Jul 30, 2024 | Aug 5, 2020 |
| Redhat_linux | — | Upgrade etcdUpgrade etcd-debuginfo | Apr 28, 2021 | Aug 5, 2020 |
| Suse | — | Upgrade kubernetes-commonUpgrade kubernetes-client | Feb 4, 2022 | Aug 5, 2020 |
| Ubuntu | — | Upgrade etcd-serverUpgrade etcd-client (Ubuntu Pro)Upgrade etcd-server (Ubuntu Pro)Upgrade etcdUpgrade etcd (Ubuntu Pro)Upgrade etcd-client | Sep 23, 2022 | Aug 5, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Aug 5, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub