{"id":"GO-2020-0005","summary":"Panic due to malformed WALs in go.etcd.io/etcd","details":"Malformed WALs can be constructed such that WAL.ReadAll can cause attempted out of bounds reads, or creation of arbitrarily sized slices, which may be used as a DoS vector.","aliases":["BIT-etcd-2020-15106","BIT-etcd-2020-15112","CVE-2020-15106","CVE-2020-15112","GHSA-m332-53r6-2w93","GHSA-p4g4-wgrh-qrg2"],"modified":"2026-02-04T03:10:38.304879Z","published":"2021-04-14T20:04:52Z","related":["CGA-92v5-v29p-6fhv"],"database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2020-0005"},"references":[{"type":"FIX","url":"https://github.com/etcd-io/etcd/pull/11793"},{"type":"FIX","url":"https://github.com/etcd-io/etcd/commit/f4b650b51dc4a53a8700700dc12e1242ac56ba07"},{"type":"WEB","url":"https://github.com/etcd-io/etcd/blob/master/security/SECURITY_AUDIT.pdf"}],"affected":[{"package":{"name":"go.etcd.io/etcd","ecosystem":"Go","purl":"pkg:golang/go.etcd.io/etcd"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.5.0-alpha.5.0.20200423152442-f4b650b51dc4"}]}],"ecosystem_specific":{"imports":[{"symbols":["Create","Repair","Verify","WAL.ReadAll","decoder.decodeRecord"],"path":"go.etcd.io/etcd/wal"}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2020-0005.json"}}],"schema_version":"1.7.3","credits":[{"name":"Trail of Bits"}]}