CVE-2020-26240
Summary
| CVE | CVE-2020-26240 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-25 02:15:00 UTC |
| Updated | 2020-12-03 15:16:00 UTC |
| Description | Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. An ethash mining DAG generation flaw in Geth before version 1.9.24 could cause miners to erroneously calculate PoW in an upcoming epoch (estimated early January, 2021). This happened on the ETC chain on 2020-11-06. This issue is relevant only for miners, non-mining nodes are unaffected. This issue is fixed as of 1.9.24 |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Bit boundary fix for the DAG generation routine by slavikus · Pull Request #21793 · ethereum/go-ethereum · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| Ethash DAG generation bug can cause miners to create invalid PoW · Advisory · ethereum/go-ethereum · GitHub |
CONFIRM |
github.com |
Third Party Advisory |
| Geth security release | Ethereum Foundation Blog |
MISC |
blog.ethereum.org |
Vendor Advisory |
| consensus/ethash: use 64bit indexes for the DAG generation (#21793) · ethereum/go-ethereum@d990df9 · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982040 Go (go) Security Update for github.com/ethereum/go-ethereum/consensus (GHSA-v592-xf75-856p)