Vulnerability Report: GO-2022-0254
- CVE-2021-39137, GHSA-9856-9gg9-qcmq
- Affects: github.com/ethereum/go-ethereum
- Published: Jul 15, 2022
- Modified: May 20, 2024
A vulnerability in the Geth EVM can cause a node to reject the canonical chain. A memory-corruption bug within the EVM can cause a consensus error, where vulnerable nodes obtain a different stateRoot when processing a maliciously crafted transaction. This, in turn, would lead to the chain being split in two forks.
Affected Packages
-
PathGo VersionsSymbols
-
before v1.10.8
Aliases
References
- https://github.com/ethereum/go-ethereum/pull/23381/commits/4d4879cafd1b3c906fc184a8c4a357137465128f
- https://vuln.go.dev/ID/GO-2022-0254.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.