{"schema_version":"1.7.3","id":"GO-2020-0005","published":"2021-04-14T20:04:52Z","modified":"2026-02-04T03:10:38.304879Z","aliases":["BIT-etcd-2020-15106","BIT-etcd-2020-15112","CVE-2020-15106","CVE-2020-15112","GHSA-m332-53r6-2w93","GHSA-p4g4-wgrh-qrg2"],"related":["CGA-92v5-v29p-6fhv"],"summary":"Panic due to malformed WALs in go.etcd.io/etcd","details":"Malformed WALs can be constructed such that WAL.ReadAll can cause attempted out of bounds reads, or creation of arbitrarily sized slices, which may be used as a DoS vector.","affected":[{"package":{"name":"go.etcd.io/etcd","ecosystem":"Go","purl":"pkg:golang/go.etcd.io/etcd"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.5.0-alpha.5.0.20200423152442-f4b650b51dc4"}]}],"ecosystem_specific":{"imports":[{"path":"go.etcd.io/etcd/wal","symbols":["Create","Repair","Verify","WAL.ReadAll","decoder.decodeRecord"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2020-0005.json"}}],"references":[{"type":"FIX","url":"https://github.com/etcd-io/etcd/pull/11793"},{"type":"FIX","url":"https://github.com/etcd-io/etcd/commit/f4b650b51dc4a53a8700700dc12e1242ac56ba07"},{"type":"WEB","url":"https://github.com/etcd-io/etcd/blob/master/security/SECURITY_AUDIT.pdf"}],"database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2020-0005"},"credits":[{"name":"Trail of Bits"}]}