Skip to content

Auto compaction retention negative value causing a compaction loop or a crash

Low
spzala published GHSA-pm3m-32r3-7mfh Aug 5, 2020

Package

embed

Affected versions

<= 3.4.9

Patched versions

3.4.10, 3.3.23

Description

Impact

Data Validation

Detail

The parseCompactionRetention function in embed/etcd.go allows the retention variable value to be negative and causes the node to execute the history compaction in a loop, taking more CPU than usual and spamming logs.

References

Find out more on this vulnerability in the security audit report

For more information

If you have any questions or comments about this advisory:

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs