Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-9gp7-6833-wv89: etcd having a negative value for cluster node size results in an index out-of-bound panic during service discovery

Vulnerability type

Data Validation

Detail

When an etcd instance attempts to perform service discovery, if a cluster size is provided as a negative value, the etcd instance will panic without recovery.

References

Find out more on this vulnerability in the security audit report

For more information

If you have any questions or comments about this advisory:

ghsa
#vulnerability#git#pdf
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. GHSA-9gp7-6833-wv89

etcd having a negative value for cluster node size results in an index out-of-bound panic during service discovery

Low severity GitHub Reviewed Published Oct 6, 2022 in etcd-io/etcd • Updated Oct 6, 2022

Package

gomod go.etcd.io/etcd/client/v3 (Go)

Affected versions

>= 3.4.0, < 3.4.10

< 3.3.23

Patched versions

3.4.10

3.3.23

Description

Vulnerability type

Data Validation

Detail

When an etcd instance attempts to perform service discovery, if a cluster size is provided as a negative value, the etcd instance will panic without recovery.

References

Find out more on this vulnerability in the security audit report

For more information

If you have any questions or comments about this advisory:

  • Contact the etcd security committee

References

  • GHSA-9gp7-6833-wv89

GHSA ID

GHSA-9gp7-6833-wv89

Source code

ghsa: Latest News

GHSA-7p9f-6x8j-gxxp: CRI-O: Maliciously structured checkpoint file can gain arbitrary node access