GHSA-pm3m-32r3-7mfh

Suggest an improvement
Source
https://github.com/advisories/GHSA-pm3m-32r3-7mfh
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-pm3m-32r3-7mfh/GHSA-pm3m-32r3-7mfh.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-pm3m-32r3-7mfh
Aliases
Related
Published
2024-02-03T00:03:07Z
Modified
2024-07-08T20:02:40Z
Summary
Etcd embed auto compaction retention negative value causing a compaction loop or a crash
Details

Impact

Data Validation

Detail

The parseCompactionRetention function in embed/etcd.go allows the retention variable value to be negative and causes the node to execute the history compaction in a loop, taking more CPU than usual and spamming logs.

References

Find out more on this vulnerability in the security audit report

For more information

If you have any questions or comments about this advisory: * Contact the etcd security committee

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [],
    "severity": "LOW",
    "github_reviewed": true,
    "github_reviewed_at": "2024-02-03T00:03:07Z"
}
References

Affected packages

Go / go.etcd.io/etcd/v3

Package

Name
go.etcd.io/etcd/v3
View open source insights on deps.dev
Purl
pkg:golang/go.etcd.io/etcd/v3

Affected ranges

Type
SEMVER
Events
Introduced
3.4.0-rc.0
Fixed
3.4.10

Database specific

{
    "last_known_affected_version_range": "<= 3.4.9"
}

Go / go.etcd.io/etcd/v3

Package

Name
go.etcd.io/etcd/v3
View open source insights on deps.dev
Purl
pkg:golang/go.etcd.io/etcd/v3

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.3.23