Denial of service in github.com/ethereum/go-ethereum
Moderate severity
GitHub Reviewed
Published
Dec 11, 2020
in
ethereum/go-ethereum
•
Updated Feb 14, 2023
Description
Reviewed
May 21, 2021
Published to the GitHub Advisory Database
Jun 29, 2021
Last updated
Feb 14, 2023
Impact
A DoS vulnerability can make a LES server crash via malicious
GetProofsV2
request from a connected LES client.Patches
The vulnerability was patched in ethereum/go-ethereum#21896.
Workarounds
This vulnerability only concerns users explicitly enabling
les
server; disablingles
prevents the exploit.It can also be patched by manually applying the patch in ethereum/go-ethereum#21896.
For more information
If you have any questions or comments about this advisory:
References