MEDIUM 6.5 Go

Denial of service in github.com/ethereum/go-ethereum

GHSA-r33q-22hv-j29q · CVE-2020-26264 · GO-2021-0063

Published · Modified

Description

Impact

A DoS vulnerability can make a LES server crash via malicious GetProofsV2 request from a connected LES client.

Patches

The vulnerability was patched in https://github.com/ethereum/go-ethereum/pull/21896.

Workarounds

This vulnerability only concerns users explicitly enabling les server; disabling les prevents the exploit.
It can also be patched by manually applying the patch in https://github.com/ethereum/go-ethereum/pull/21896.

For more information

If you have any questions or comments about this advisory:

Ready to move

Start Securing

Free, no credit card | First findings in minutes