Launch Week Day 1: Announcing Security Design Review
UNKNOWN Go

Etcd embed auto compaction retention negative value causing a compaction loop or a crash

GHSA-pm3m-32r3-7mfh · GO-2024-2529

Published · Modified

Description

Impact

Data Validation

Detail

The parseCompactionRetention function in embed/etcd.go allows the retention variable value to be negative and causes the node to execute the history compaction in a loop, taking more CPU than usual and spamming logs.

References

Find out more on this vulnerability in the security audit report

For more information

If you have any questions or comments about this advisory:

Ready to move

Start Securing

Free, no credit card | First findings in minutes