Severity
7.5HIGHNVD
CNA6.5
EPSS
0.5%
top 33.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 25
Latest updateJul 28

Description

Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth before version 1.9.18, there is a Denial-of-service (crash) during block processing. This is fixed in 1.9.18.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

CVEListV5ethereum/go-ethereum< 1.9.18
NVDethereum/go_ethereum< 1.9.18
Gogithub.com/ethereum_go-ethereum1.9.161.9.18
Gogithub.com/holiman_uint2560.1.01.1.1

🔴Vulnerability Details

4
OSV
Denial of service in github.com/holiman/uint2562021-07-28
OSV
Denial of service in geth2021-06-29
GHSA
Denial of service in geth2021-06-29
CVEList
Denial of service in geth2020-11-25
CVE-2020-26242 — Out-of-bounds Read in Go-ethereum | cvebase