First published: Tue Apr 27 2021(Updated: )
The etcd packages provide a highly available key-value store for shared configuration.<br>Security Fix(es):<br><li> etcd: Large slice causes panic in decodeRecord method (CVE-2020-15106)</li> <li> etcd: DoS in wal/wal.go (CVE-2020-15112)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/etcd | <3.2.32-1.el7_9 | 3.2.32-1.el7_9 |
redhat/etcd | <3.2.32-1.el7_9 | 3.2.32-1.el7_9 |
redhat/etcd-debuginfo | <3.2.32-1.el7_9 | 3.2.32-1.el7_9 |
redhat/etcd-debuginfo | <3.2.32-1.el7_9 | 3.2.32-1.el7_9 |
redhat/etcd | <3.2.32-1.el7_9 | 3.2.32-1.el7_9 |
redhat/etcd-debuginfo | <3.2.32-1.el7_9 | 3.2.32-1.el7_9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2021:1407 is classified as moderate.
RHSA-2021:1407 addresses CVE-2020-15106 and CVE-2020-15112 which can cause panic and denial of service respectively.
To fix RHSA-2021:1407, update the etcd package to version 3.2.32-1.el7_9.
Versions of etcd prior to 3.2.32-1.el7_9 are affected by RHSA-2021:1407.
The vulnerabilities in RHSA-2021:1407 can lead to application crashes and potential denial of service conditions.