SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-26265

In Geth from version 1.9.4 and before version 1.9.20 a consensus-vulnerability could cause a chain split, where vulnerable versions refuse to accept the canonical chain.

MEDIUM 5.3EPSS 0.92%

Does this matter?

Lower severity and a low EPSS score (0.92%). Track it; it rarely justifies an emergency change on its own.

Description

Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth from version 1.9.4 and before version 1.9.20 a consensus-vulnerability could cause a chain split, where vulnerable versions refuse to accept the canonical chain. The fix was included in the Paragade release version 1.9.20. No individual workaround patches have been made -- all users are recommended to upgrade to a newer version.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS
0.92% probability · 58th percentile
CISA KEV
Not listed
Weakness
CWE-682
Affected
ethereum/go ethereum
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.