Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2020-15106

etcd: forged WAL frame size panics decodeRecord

Technology

etcd

CVSS Score

6.5 / 10.0

Affected Versions

etcd before 3.3.23, 3.4.0 to 3.4.9

Upstream Fix

3.3.23, 3.4.10

Published

August 5, 2020

OSSeva Coverage

Fixed upstream

Description

The size of a WAL record is read from the file without validation, so a forged, very large frame size makes any Raft member that decodes the WAL panic.

Upstream record: NVD · CVE.org

Is your etcd deployment affected?

If you're running etcd before 3.3.23, 3.4.0 to 3.4.9, you need this patch. Book a discovery call to get covered.