go-ethereum vulnerable to DoS via malicious p2p message
Description
Published to the GitHub Advisory Database
May 6, 2024
Reviewed
May 6, 2024
Published by the National Vulnerability Database
May 6, 2024
Last updated
May 9, 2024
Impact
A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node.
More in-depth details will be released at a later time.
Patches
The fix has been included in geth version
1.13.15
and onwards.Workarounds
No workarounds have been made public.
References
No more information is released at this time.
Credit
This issue was disclosed responsibly by DongHan Kim via the Ethereum bug bounty program. Thank you for your cooperation.
References