VDB
CVE-2020-26240
CVE-2020-26240
PUBLISHED
CVSS 7.5 HIGH
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. An ethash mining DAG generation flaw in Geth before version 1.9.24 could cause miners to erroneously calculate PoW in an upcoming epoch (estimated early January, 2021). This happened on the ETC chain on 2020-11-06. This issue is relevant only for miners, non-mining nodes are unaffected. This issue is fixed as of 1.9.24
EPSS 1.66% · 75.3th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
1.66%
75.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | ethereum/go-ethereum/cmd/evm | 0, 0, 0 |
| github.com | ethereum/go-ethereum | 0, 0, 0 |
| github.com | ethereum/go-ethereum/eth | 0, 0, 0 |
| github.com | ethereum/go-ethereum/consensus | 0, 0, 0 |
| ethereum | go-ethereum | < 1.9.24, < 1.9.24, < 1.9.24 |
Timeline
- Nov 25, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 25, 2021 EPSS Score
- Dec 28, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 1, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 3, 2022 EPSS Score
- Sep 6, 2022 EPSS Score
- Nov 8, 2022 EPSS Score
References
- https://blog.ethereum.org/2020/11/12/geth_security_release url
- https://github.com/ethereum/go-ethereum url
- https://blog.ethereum.org/2020/11/12/geth_security_release/ url
- https://github.com/ethereum/go-ethereum/security/advisories/GHSA-v592-xf75-856p url
- https://nvd.nist.gov/vuln/detail/CVE-2020-26240 advisory
- https://github.com/ethereum/go-ethereum/pull/21793 patch
- https://github.com/ethereum/go-ethereum/commit/d990df909d7839640143344e79356754384dcdd0 patch
- https://github.com/advisories/GHSA-v592-xf75-856p advisory