Lucene search

K
osvGoogleOSV:GHSA-PM3M-32R3-7MFH
HistoryFeb 03, 2024 - 12:03 a.m.

Etcd embed auto compaction retention negative value causing a compaction loop or a crash

2024-02-0300:03:07
Google
osv.dev
6
etcd
embed
compaction
retention
negative value
data validation
security
vulnerability

7.3 High

AI Score

Confidence

High

Impact

Data Validation

Detail

The parseCompactionRetention function in embed/etcd.go allows the retention variable value to be negative and causes the node to execute the history compaction in a loop, taking more CPU than usual and spamming logs.

References

Find out more on this vulnerability in the security audit report

For more information

If you have any questions or comments about this advisory:

7.3 High

AI Score

Confidence

High