Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2020-15112

etcd: WAL entry index beyond the entry count panics ReadAll

Technology

etcd

CVSS Score

6.5 / 10.0

Affected Versions

etcd before 3.3.23, 3.4.0 to 3.4.9

Upstream Fix

3.3.23, 3.4.10

Published

August 5, 2020

OSSeva Coverage

Fixed upstream

Description

A WAL entry index greater than the number of entries causes a runtime panic in the ReadAll method of wal/wal.go, which can take down a member while it reads WAL entries during consensus.

Upstream record: NVD · CVE.org

Is your etcd deployment affected?

If you're running etcd before 3.3.23, 3.4.0 to 3.4.9, you need this patch. Book a discovery call to get covered.