MEDIUM 6.5 Go
Denial of service in github.com/ethereum/go-ethereum
GHSA-r33q-22hv-j29q · CVE-2020-26264 · GO-2021-0063
Published · Modified
Description
Impact
A DoS vulnerability can make a LES server crash via malicious GetProofsV2 request from a connected LES client.
Patches
The vulnerability was patched in https://github.com/ethereum/go-ethereum/pull/21896.
Workarounds
This vulnerability only concerns users explicitly enabling les server; disabling les prevents the exploit.
It can also be patched by manually applying the patch in https://github.com/ethereum/go-ethereum/pull/21896.
For more information
If you have any questions or comments about this advisory:
- Open an issue in go-ethereum
- Email us at security@ethereum.org
References
- WEB https://github.com/ethereum/go-ethereum/security/advisories/GHSA-r33q-22hv-j29q
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2020-26264
- WEB https://github.com/ethereum/go-ethereum/pull/21896
- WEB https://github.com/ethereum/go-ethereum/commit/bddd103a9f0af27ef533f04e06ea429cf76b6d46
- PACKAGE https://github.com/ethereum/go-ethereum
- WEB https://github.com/ethereum/go-ethereum/releases/tag/v1.9.25
- WEB https://pkg.go.dev/vuln/GO-2021-0063
Ready to move
Start Securing
Free, no credit card | First findings in minutes