CVE-2022-23328: High severity Ethereum Go Ethereum vulnerability
A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, which can purge all of pending transactions in a victim node's memory pool and then occupy the memory pool to prevent new transactions from entering the pool, resulting in a denial of service (DoS).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this design flaw in Go-Ethereum?
The vulnerability ID for this design flaw in Go-Ethereum is CVE-2022-23328.
What is the severity of CVE-2022-23328?
The severity of CVE-2022-23328 is high with a CVSS score of 7.5.
What is the affected software for CVE-2022-23328?
The affected software for CVE-2022-23328 is Ethereum Go Ethereum.
How does the design flaw in Go-Ethereum affect the victim node?
The design flaw in Go-Ethereum allows an attacker node to send multiple pending transactions of a high gas price to a victim node, which can cause all pending transactions to be purged from the victim node's memory pool.
Are there any references available for CVE-2022-23328?
Yes, references for CVE-2022-23328 can be found at the following links: [http://ethereum.com](http://ethereum.com), [http://go-ethereum.com](http://go-ethereum.com), [https://dl.acm.org/doi/pdf/10.1145/3460120.3485369](https://dl.acm.org/doi/pdf/10.1145/3460120.3485369).