{"id":"GHSA-m6gx-rhvj-fh52","aliases":["GO-2022-0392"],"url":"https://o3.security/vulnerability/GHSA-m6gx-rhvj-fh52","summary":"Denial of service in go-ethereum due to CVE-2020-28362","details":"### Impact\nVersions of Geth built with Go `<1.15.5` or `<1.14.12` are most likely affected by a critical DoS-related security vulnerability. The golang team has registered the underlying flaw as ‘CVE-2020-28362’.\n\nWe recommend all users to rebuild (ideally `v1.9.24`) with Go `1.15.5` or `1.14.12`, to avoid node crashes. Alternatively, if you are running binaries distributed via one of our official channels, we’re going to release `v1.9.24` ourselves built with Go `1.15.5`.\n\n### Patches\nThis is not an issue in go-ethereum, rebuilding an older version with Go `1.15.5` or `1.14.12` will suffice to address the vulnerability. \n\n### Workarounds\nRebuilding with Go `1.15.5` or `1.14.12` will suffice to address the vulnerability. \n\n### References\n- https://blog.ethereum.org/2020/11/12/geth_security_release/\n- https://groups.google.com/g/golang-announce/c/NpBGTTmKzpM\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [go-ethereum](https://github.com/ethereum/go-ethereum)\n* Email us at [security@ethereum.org](mailto:security@ethereum.org)\n","published":"2021-06-29T21:13:54Z","modified":"2025-01-30T14:37:03Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/ethereum/go-ethereum","fixedVersion":"1.9.24"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/ethereum/go-ethereum/security/advisories/GHSA-m6gx-rhvj-fh52"},{"type":"PACKAGE","url":"https://github.com/ethereum/go-ethereum"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-01-30T14:37:03Z"}}