CVE-2021-43668: Null Pointer Dereference
Go-Ethereum 1.10.9 nodes crash (denial of service) after receiving a serial of messages and cannot be recovered. They will crash with "runtime error: invalid memory address or nil pointer dereference" and arise a SEGV signal.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-43668?
The severity of CVE-2021-43668 is medium with a severity value of 5.5.
How does CVE-2021-43668 affect Go-Ethereum nodes?
CVE-2021-43668 causes Go-Ethereum 1.10.9 nodes to crash and become unrecoverable after receiving a series of messages.
Why do Go-Ethereum 1.10.9 nodes crash after receiving messages?
Go-Ethereum 1.10.9 nodes crash due to a runtime error: invalid memory address or nil pointer dereference, resulting in a SEGV signal.
How can I mitigate CVE-2021-43668?
Currently, there is no known fix or mitigation for CVE-2021-43668. It is recommended to update to a patched version of Go-Ethereum once available.
Where can I find more information about CVE-2021-43668?
You can find more information about CVE-2021-43668 on NIST's National Vulnerability Database (NVD) at https://nvd.nist.gov/vuln/detail/CVE-2021-43668.