CVE-2022-34038: High severity Etcd Etcd vulnerability
Published Aug 22, 2023
·Updated
DISPUTED Etcd v3.5.4 allows remote attackers to cause a denial of service via function PageWriter.write in pagewriter.go. NOTE: the vendor's position is that this is not a vulnerability.
Affected Software
2 affected componentsFixes available
go/go.etcd.io/etcd/v3<3.5.5
3.5.5
Etcd Etcd=3.5.4
Remediation
Patch Available
Patch Available
Event History
Aug 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Disputed
07:16 PM
Advisory Published
via GitHub·09:30 PM
Aug 31, 2023
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Oct 9, 2023
Withdrawn
via GitHub·09:46 PM
Frequently Asked Questions
1
What is CVE-2022-34038?
CVE-2022-34038 is a vulnerability in Etcd v3.5.4 that allows remote attackers to cause a denial of service.
2
What is the severity of CVE-2022-34038?
CVE-2022-34038 has a severity rating of 7.5 (High).
3
How does CVE-2022-34038 work?
CVE-2022-34038 exploits a vulnerability in the PageWriter.write function in pagewriter.go, allowing remote attackers to cause a denial of service.
4
Which versions of Etcd are affected by CVE-2022-34038?
Etcd v3.5.4 is affected by CVE-2022-34038.
5
How can I fix CVE-2022-34038?
To fix CVE-2022-34038, upgrade to Etcd v3.5.5 or higher.