Asymmetric denial of service - ReDoS In github.com/ethereum/go-ethereum
Description
go-ethereum is vulnerable to high CPU usage leading to DoS via malicious p2p message Impact
An attacker can cause high CPU usage by sending a specially crafted p2p message. More details to be released later.
Credit
This issue was reported to the Ethereum Foundation Bug Bounty Program by @Yenya030
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
go | 1.16.8 |
Aliases
1. 2. 3. 4. 5.
References
1. 2.