Skip to content

LES Server DoS via GetProofsV2

Moderate
fjl published GHSA-r33q-22hv-j29q Dec 11, 2020

Package

go-ethereum (golang)

Affected versions

<v1.9.25

Patched versions

v1.9.25

Description

Impact

A DoS vulnerability can make a LES server crash via malicious GetProofsV2 request from a connected LES client.

Patches

The vulnerability was patched in #21896.

Workarounds

This vulnerability only concerns users explicitly enabling les server; disabling les prevents the exploit.
It can also be patched by manually applying the patch in #21896.

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

CVE-2020-26264

Weaknesses

No CWEs

Credits