CVE-2020-26240
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. An ethash mining DAG generation flaw in Geth before version 1.9.24 could cause miners to erroneously calculate PoW in an upcoming epoch (estimated early January, 2021). This happened on the ETC chain on 2020-11-06. This issue is relevant only for miners, non-mining nodes are unaffected. This issue is fixed as of 1.9.24
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.66% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-682
- Affected
- ethereum/go ethereum
- Source
- security-advisories@github.com
References
- https://blog.ethereum.org/2020/11/12/geth_security_release/Vendor Advisory
- https://github.com/ethereum/go-ethereum/commit/d990df909d7839640143344e79356754384dcdd0Patch, Third Party Advisory
- https://github.com/ethereum/go-ethereum/pull/21793Patch, Third Party Advisory
- https://github.com/ethereum/go-ethereum/security/advisories/GHSA-v592-xf75-856pThird Party Advisory
- https://blog.ethereum.org/2020/11/12/geth_security_release/Vendor Advisory
- https://github.com/ethereum/go-ethereum/commit/d990df909d7839640143344e79356754384dcdd0Patch, Third Party Advisory
- https://github.com/ethereum/go-ethereum/pull/21793Patch, Third Party Advisory
- https://github.com/ethereum/go-ethereum/security/advisories/GHSA-v592-xf75-856pThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.