VDB
Sign up
MEDIUM6.5

GHSA-r33q-22hv-j29q

Denial of service in github.com/ethereum/go-ethereum

Quick fix

GHSA-r33q-22hv-j29q — github.com/ethereum/go-ethereum: upgrade to the fixed version with the command below.

go get github.com/ethereum/go-ethereum@v1.9.25

Details

### Impact

A DoS vulnerability can make a LES server crash via malicious `GetProofsV2` request from a connected LES client.

### Patches

The vulnerability was patched in https://github.com/ethereum/go-ethereum/pull/21896.

### Workarounds

This vulnerability only concerns users explicitly enabling `les` server; disabling `les` prevents the exploit. It can also be patched by manually applying the patch in https://github.com/ethereum/go-ethereum/pull/21896.

### For more information If you have any questions or comments about this advisory: * Open an issue in [go-ethereum](https://github.com/ethereum/go-ethereum) * Email us at [security@ethereum.org](mailto:security@ethereum.org)

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/ethereum/go-ethereum
Introduced in: 0Fixed in: 1.9.25
Fixgo get github.com/ethereum/go-ethereum@v1.9.25

References