← Vulnerability feed

Vulnerability record · CVE-2022-34038 · published 22 August 2023

CVE-2022-34038: Etcd out-of-bounds write vulnerability

Etcd · Etcd

Etcd v3.5.4 allows remote attackers to cause a denial of service via function PageWriter.write in pagewriter.go. NOTE: the vendor's position is that this is not a vulnerability.

7.5 CVSS 3.1 High EPSS 1.8% · top 23.0% CWE-787 · Out-of-bounds write
7.5CVSS 3.1 base score
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

Etcd v3.5.4 allows remote attackers to cause a denial of service via function PageWriter.write in pagewriter.go. NOTE: the vendor's position is that this is not a vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-34038 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-28235Etcd improper authentication vulnerabilityAuthentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.EPSS 1.6%8.8CVE-2026-33413Etcd missing authorization vulnerabilityetcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, unauthorized users may bypas…EPSS 0.34%8.1CVE-2026-59818Etcd improper certificate validation vulnerabilityetcd is a distributed key-value store for the data of a distributed system. Prior to 3.5.32 and 3.6.13, when etcd is configured with --listen-client-…EPSS 0.43%8.1CVE-2018-16886Etcd improper authentication vulnerabilityetcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is…EPSS 4.0%7.1CVE-2020-15113Etcd vulnerabilityIn etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatic…EPSS 0.23%6.5CVE-2026-33343Etcd incorrect authorization vulnerabilityetcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, an authenticated user with R…EPSS 0.26%6.5CVE-2020-15112Etcd improper input validation vulnerabilityIn etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index greater then the number of entries in the ReadAll method in wal/wal.…EPSS 1.3%6.5CVE-2020-15106Etcd improper input validation vulnerabilityIn etcd before versions 3.3.23 and 3.4.10, a large slice causes panic in decodeRecord method. The size of a record is stored in the length field of a…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2022-34038), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.