Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-30636: failed to start node: Grpc · Issue #14517 · tikv/tikv

TiKV 6.1.2 allows remote attackers to cause a denial of service (fatal error, with RpcStatus UNAVAILABLE for “not leader”) upon an attempt to start a node in a situation where the context deadline is exceeded

CVE
#ubuntu#dos

Bug Report****What version of TiKV are you using?

V6.1.2

What operating system and CPU are you using?

ubuntu

Steps to reproduce

Run Jepsen test configured with the set workload and the kill/pause/partition nemesis.

What did you expect?

No fatal

What happened?

./tikv set/20230330T224351.032Z/n2/kv.log:[2023/03/30 22:54:59.466 +00:00] [FATAL] [server.rs:955] ["failed to start node: Grpc(RpcFailure(RpcStatus { code: 14-UNAVAILABLE, message: "not leader", details: [] }))"]

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907