CVE-2020-26242: Denial of service in geth

Published Nov 25, 2020
·
Updated

Impact Denial-of-service (crash) during block processing

Details

Affected versions suffer from a vulnerability which can be exploited through the MULMOD operation, by specifying a modulo of 0: mulmod(a,b,0), causing a panic in the underlying library. The crash was in the uint256 library, where a buffer underflowed.

if d == 0, dLen remains 0

and https://github.com/holiman/uint256/blob/4ce82e695c10ddad57215bdbeafb68b8c5df2c30/uint256.go#L451 will try to access index [-1].

The uint256 library was first merged in this commit, on 2020-06-08. Exploiting this vulnerabilty would cause all vulnerable nodes to drop off the network.

The issue was brought to our attention through a bug report, showing a panic occurring on sync from genesis on the Ropsten network. It was estimated that the least obvious way to fix this would be to merge the fix into uint256, make a new release of that library and then update the geth-dependency.

- https://github.com/holiman/uint256/releases/tag/v1.1.1 was made the same day, - PR to address the issue: https://github.com/holiman/uint256/pull/80 - PR to update geth deps: https://github.com/ethereum/go-ethereum/pull/21368

Patches

Upgrade to v1.9.18 or higher

Workarounds

Not at this time

References

https://blog.ethereum.org/2020/11/12/gethsecurityrelease/ For more information If you have any questions or comments about this advisory: Open an issue in go-ethereum Email us at security@ethereum.org

Other sources

Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth before version 1.9.18, there is a Denial-of-service (crash) during block processing. This is fixed in 1.9.18.

MITRE

Affected Software

3 affected componentsFixes available
go/github.com/holiman/uint256>=0.1.0<1.1.1
1.1.1
go/github.com/ethereum/go-ethereum>=1.9.16<1.9.18
1.9.18
Ethereum Go Ethereum<1.9.18

Event History

Nov 25, 2020
CVE Published
via MITRE·01:25 AM
Data Sourced
via MITRE·01:25 AM
DescriptionSeverityWeakness
Jun 29, 2021
Advisory Published
via GitHub·09:13 PM
Data Sourced
via GitHub·09:13 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is CVE-2020-26242?

CVE-2020-26242 is a vulnerability in Go Ethereum (Geth) that allows for a denial-of-service (crash) during block processing.

2

What version of Go Ethereum is affected by CVE-2020-26242?

Versions of Go Ethereum before 1.9.18 are affected by CVE-2020-26242.

3

How severe is CVE-2020-26242?

CVE-2020-26242 has a severity level of high, with a CVSS score of 7.5.

4

How can I fix CVE-2020-26242?

To fix CVE-2020-26242, you need to update to version 1.9.18 or higher of Go Ethereum (Geth).

5

Where can I find more information about CVE-2020-26242?

You can find more information about CVE-2020-26242 on the Ethereum blog at https://blog.ethereum.org/2020/11/12/geth_security_release/ and on the GitHub page at https://github.com/ethereum/go-ethereum/security/advisories/GHSA-jm5c-rv3w-w83m.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203