GHSA-r33q-22hv-j29q
Denial of service in github.com/ethereum/go-ethereum
Quick fix
GHSA-r33q-22hv-j29q — github.com/ethereum/go-ethereum: upgrade to the fixed version with the command below.
go get github.com/ethereum/go-ethereum@v1.9.25Details
### Impact
A DoS vulnerability can make a LES server crash via malicious `GetProofsV2` request from a connected LES client.
### Patches
The vulnerability was patched in https://github.com/ethereum/go-ethereum/pull/21896.
### Workarounds
This vulnerability only concerns users explicitly enabling `les` server; disabling `les` prevents the exploit. It can also be patched by manually applying the patch in https://github.com/ethereum/go-ethereum/pull/21896.
### For more information If you have any questions or comments about this advisory: * Open an issue in [go-ethereum](https://github.com/ethereum/go-ethereum) * Email us at [security@ethereum.org](mailto:security@ethereum.org)
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.9.25go get github.com/ethereum/go-ethereum@v1.9.25References
- https://github.com/ethereum/go-ethereum/security/advisories/GHSA-r33q-22hv-j29q[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2020-26264[ADVISORY]
- https://github.com/ethereum/go-ethereum/pull/21896[WEB]
- https://github.com/ethereum/go-ethereum/commit/bddd103a9f0af27ef533f04e06ea429cf76b6d46[WEB]
- https://github.com/ethereum/go-ethereum[PACKAGE]
- https://github.com/ethereum/go-ethereum/releases/tag/v1.9.25[WEB]
- https://pkg.go.dev/vuln/GO-2021-0063[WEB]