CVE-2022-37450: Medium severity ethereum blockchain vulnerability
Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-chain blocks, aka Riskless Uncle Making (RUM), as exploited in the wild in 2020 through 2022.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-37450?
CVE-2022-37450 is a vulnerability in Go Ethereum (geth) where attackers can increase rewards by mining blocks in certain situations and manipulating time-difference values to replace main-chain blocks.
How does CVE-2022-37450 affect Go Ethereum?
CVE-2022-37450 affects Go Ethereum versions up to and including 1.10.21.
What is Riskless Uncle Making (RUM)?
Riskless Uncle Making (RUM) is the name given to the exploitation of CVE-2022-37450, where attackers manipulate time-difference values to replace main-chain blocks and increase rewards.
What is the severity of CVE-2022-37450?
CVE-2022-37450 has a severity rating of 5.9 (medium).
How can I mitigate the CVE-2022-37450 vulnerability?
To mitigate the CVE-2022-37450 vulnerability, it is recommended to update to a version of Go Ethereum that is higher than 1.10.21.