CVE-2020-26264: LES Server DoS via GetProofsV2
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth before version 1.9.25 a denial-of-service vulnerability can make a LES server crash via malicious GetProofsV2 request from a connected LES client. This vulnerability only concerns users explicitly enabling les server; disabling les prevents the exploit. The vulnerability was patched in version 1.9.25.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability CVE-2020-26264?
The vulnerability CVE-2020-26264 is a denial-of-service vulnerability in Go Ethereum (Geth) before version 1.9.25.
How can the vulnerability CVE-2020-26264 be exploited?
The vulnerability CVE-2020-26264 can be exploited by sending a malicious GetProofsV2 request from a connected LES client, causing a crash in the LES server.
Which version of Go Ethereum (Geth) is affected by CVE-2020-26264?
Go Ethereum (Geth) before version 1.9.25 is affected by CVE-2020-26264.
What is the severity of the vulnerability CVE-2020-26264?
The severity of the vulnerability CVE-2020-26264 is medium with a CVSS score of 6.5.
How can I fix the vulnerability CVE-2020-26264?
To fix the vulnerability CVE-2020-26264, users should update to Geth version 1.9.25 or later.