Lack of data validation In github.com/ethereum/go-ethereum
Description
go-ethereum is vulnerable to DoS via malicious p2p message affecting a vulnerable node Impact
A vulnerable node can be forced to shutdown/crash using a specially crafted message. More details to be released later.
Credit
This issue was reported to the Ethereum Foundation Bug Bounty Program by DELENE TCHIO ROMUALD.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
go | 1.16.8 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.