HIGHGo →
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
Affected packages
- go.etcd.io/etcd/v3
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/etcd-io/etcd/security/advisories/GHSA-6vch-q96h-7gc3
- https://github.com/etcd-io/etcd/pull/22130
- https://github.com/etcd-io/etcd/commit/2e07efce9745004eb4773cffaada9b5cdf77cff2
- https://github.com/etcd-io/etcd/commit/f73cba7d920019f91a1ea1f6697833e42731f057
- https://github.com/etcd-io/etcd
- https://github.com/etcd-io/etcd/releases/tag/v3.5.33
- https://github.com/etcd-io/etcd/releases/tag/v3.6.14
- https://github.com/etcd-io/etcd/releases/tag/v3.7.1
Structured record: https://osv.dev/vulnerability/GHSA-6vch-q96h-7gc3
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta