{"id":"GHSA-pm3m-32r3-7mfh","aliases":["GO-2024-2529"],"url":"https://o3.security/vulnerability/GHSA-pm3m-32r3-7mfh","summary":"Etcd embed auto compaction retention negative value causing a compaction loop or a crash","details":"### Impact\nData Validation\n\n### Detail\nThe parseCompactionRetention function in embed/etcd.go allows the retention variable value to be negative and causes the node to execute the history compaction in a loop, taking more CPU than usual and spamming logs.\n\n### References\nFind out more on this vulnerability in the [security audit report](https://github.com/etcd-io/etcd/blob/master/security/SECURITY_AUDIT.pdf)\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Contact the [etcd security committee](https://github.com/etcd-io/etcd/blob/master/security/security-release-process.md#product-security-committee-psc)","published":"2024-02-03T00:03:07Z","modified":"2026-09-10T03:50:06.341542957Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"go.etcd.io/etcd/v3","fixedVersion":"3.4.10"},{"ecosystem":"Go","name":"go.etcd.io/etcd/v3","fixedVersion":"3.3.23"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/etcd-io/etcd/security/advisories/GHSA-pm3m-32r3-7mfh"},{"type":"PACKAGE","url":"https://github.com/etcd-io/etcd"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:50:06.341542957Z"}}