Bug 1179985 - (CVE-2020-26264) [network:cryptocurrencies] CVE-2020-26264: geth: In Geth before version 1.9.25 a denial-of-service vulnerability can make a LES server crash via malicious GetProofsV2 request fro
(CVE-2020-26264)
[network:cryptocurrencies] CVE-2020-26264: geth: In Geth before version 1.9.2...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P5 - None : Minor
: ---
Assigned To: Markus Reckwerth
Security Team bot
https://smash.suse.de/issue/273242/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2020-12-14 06:29 UTC by Marcus Meissner
Modified: 2020-12-14 07:50 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2020-12-14 06:29:09 UTC
CVE-2020-26264

Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum
protocol. In Geth before version 1.9.25 a denial-of-service vulnerability can
make a LES server crash via malicious GetProofsV2 request from a connected LES
client. This vulnerability only concerns users explicitly enabling les server;
disabling les prevents the exploit. The vulnerability was patched in version
1.9.25.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-26264
https://github.com/ethereum/go-ethereum/releases/tag/v1.9.25
https://github.com/ethereum/go-ethereum/security/advisories/GHSA-r33q-22hv-j29q
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26264
https://github.com/ethereum/go-ethereum/commit/bddd103a9f0af27ef533f04e06ea429cf76b6d46
https://github.com/ethereum/go-ethereum/pull/21896
Comment 1 Markus Reckwerth 2020-12-14 07:50:01 UTC
geth has been updated to 1.9.25.