Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Bitcoin nears ‘tyranny of numbers’ moment as quantum hardware matures

    December 13, 2025

    UK street gang launders drug funds with memecoin, report

    December 13, 2025

    What If Ethereum Lived on a Treap? Or, Blockchains Charging Rent

    December 13, 2025
    Facebook X (Twitter) Instagram
    Ai Crypto TimesAi Crypto Times
    • Altcoins
      • Bitcoin
      • Coinbase
      • Litecoin
    • Blockchain
    • Crypto
    • Ethereum
    • Lithosphere News Releases
    X (Twitter) Instagram YouTube LinkedIn
    Ai Crypto TimesAi Crypto Times
    Home » Geth security release | Ethereum Foundation Blog

    Geth security release | Ethereum Foundation Blog

    Michael JohnsonBy Michael JohnsonNovember 30, 2025No Comments5 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Summary

    Versions of geth built with Go <1.15.5 or <1.14.12 are most likely affected by a critical DoS-related security vulnerability. The golang team has registered this flaw as ‘CVE-2020-28362’.

    We recommend all users to rebuild (ideally v1.9.24) with Go 1.15.5 or 1.14.12, to avoid node crashes. Alternatively, if you are running binaries distributed via one of our official channels, we’re going to release v1.9.24 ourselves built with Go 1.15.5.

    Docker images will most probably be out of date due to a missing base image, but you can check the release notes on how to temporarily build one with Go 1.15.5. Please run geth version to verify the Go version your binary was built with.

    Background

    In early October, go-ethereum enrolled into Google’s OSS-Fuzz program. We had previosly executed fuzzers on an ad-hoc basis and tested some different platforms.

    On 2020-10-24, we were notified that one of our fuzzers had found a crash.

    Upon investigation, it turned out that the root cause of the issue was a bug in the standard libraries of Go, and the issue was reported upstream.

    Special thanks to Adam Korczynski of Ada Logics for the initial integration of go-ethereum into OSS-Fuzz!

    Impact

    The DoS issue can be used to crash all Geth nodes during block processing, the effects of which would be that a major part of the Ethereum network went offline.

    Outside of Go-Ethereum, the issue is most likely relevant for all forks of Geth (such as TurboGeth or ETC’s core-geth). For an even wider context, we would refer to upstream, as the Go-team have performed an investigation of potentially affected parties.

    Timeline

    • 2020-10-24: Crash report from OSS-fuzz
    • 2020-10-25: Investigation found that it was due to flaw in Go. Details sent to [email protected]
    • 2020-10-26: Acknowledgement from upstream, investigation ongoing
    • 2020-10-26 — 2020-11-06: Potential fixes discussed, upstream investigation of potentially affected parties
    • 2020-11-06: Upstream tentatively scheduled fix-release for 2020-11-12
    • 2020-11-09: Upstream pre-announced the security release: https://groups.google.com/g/golang-announce/c/kMa3eup0qhU/m/O5RSMHO_CAAJ
    • 2020-11-11: Notified users about the upcoming release via the official Geth twitter account, our official Discord-channel and Reddit.
    • 2020-11-12: New Go version were released, and new geth binaries were released

    Additional issues

    Mining flaw

    Another security issue was brought to our attention via this PR, containing a fix to the ethash algorithm.

    The mining flaw could cause miners to erroneously calculate PoW in an upcoming epoch. This happened on the ETC chain on 2020-11-06. It appears that this would be an issue for ETH mainnet around block 11550000 / epoch 385, which will occur early January 2021.

    This issue is also fixed as of 1.9.24. This issue is relevant only for miners, non-mining nodes are unaffected.

    Geth shallow copy bug

    Affected: 1.9.7 – 1.9.16

    Fixed: 1.9.17

    Type: Consensus vulnerability

    On 2020-07-15, John Youngseok Yang (Software Platform Lab) reported a consensus vulnerability in Geth.

    Geth’s pre-compiled dataCopy(0x00…04) contract did a shallow copy on invocation, whereas Parity’s did a deep copy. An attacker could deploy a contract that

    • writes X to an EVM memory region R,
    • calls 0x00..04 with R as an argument,
    • overwrites R to Y,
    • and finally invokes the RETURNDATACOPY opcode.
    • When this contract is invoked, Parity would push X on the EVM stack, whereas Geth would push Y.

    Consequences

    This was exploited on Ethereum Mainnet at block 11234873, transaction 0x57f7f9. Nodes were dropped off the network, causing ~30 blocks to be lost on a sidechain. It also caused Infura to drop off, which caused problems for a lot of people and services who were depending on Infura as a backend provider.

    More context can be found in the Geth post-mortem and Infura post-mortem and here.

    DoS in .16 and .17

    Affected: v1.9.16,v1.9.17

    Fixed: v1.9.18

    Type: DoS vulnerability during block processing

    A DoS vulnerability was found, and fixed in v1.9.18. We have chosen to not publish the details at this point in time.

    Recommendations

    In the short term, we recommend that all users upgrade to geth version v1.9.24 (which should be built with Go 1.15.5) immediately. Official releases can be found here.

    If you are using Geth via Docker, there could be a few problems. If you are using ethereum/client-go, there are two things to be aware of:

    1. There might be a delay before the new image appears on docker hub.
    2. Unless the Go base images have been created quickly enough, there’s a chance that they become built with a vulnerable version of Go.

    If you are building docker images yourself, (via docker build . from the repository root), then the second issue might be cause problems for you aswell.

    So be careful to ensure that Go 1.15.5 is used as the base image.

    In the long term, we recommend that users and miners look into alternative clients too. It is our strong feeling that the resilience of the Ethereum network should not depend on any single client implementation.
    There is Besu, Nethermind, OpenEthereum and TurboGeth and others to choose from aswell.

    Please report security vulnerabilities either via https://bounty.ethereum.org, or via [email protected] or via [email protected].





    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Michael Johnson

    Related Posts

    What If Ethereum Lived on a Treap? Or, Blockchains Charging Rent

    December 13, 2025

    Ethereum Project Update | Ethereum Foundation Blog

    December 13, 2025

    On Mining | Ethereum Foundation Blog

    December 13, 2025
    Leave A Reply Cancel Reply

    Don't Miss

    Bitcoin nears ‘tyranny of numbers’ moment as quantum hardware matures

    Crypto December 13, 2025

    Quantum hardware is exiting proof-of-concept, but engineering bottlenecks mean practical, large-scale systems remain decades away.…

    UK street gang launders drug funds with memecoin, report

    December 13, 2025

    What If Ethereum Lived on a Treap? Or, Blockchains Charging Rent

    December 13, 2025

    Bitcoin bulls risk AI-fueled spillover as bubble fears grow at $90k

    December 13, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Our Picks

    AGII Introduces Multi-Domain Insight Processor to Enhance Analytical Speed Across Web3 Systems

    December 11, 2025

    AGII Deploys Adaptive Integrity Core for Autonomous Contract-Level Verification

    December 10, 2025

    AGII Launches Predictive Threshold Engine to Strengthen Data-Driven Blockchain Intelligence

    December 8, 2025

    AGII Releases High-Gradient Decision Sequencer to Boost Next-Gen Blockchain Intelligence

    December 5, 2025

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    • Popular
    • Recent
    • Top Reviews

    Crypto wrap: Bitcoin’s sharp fall drags Ethereum, XRP, Solana and BNB lower

    October 19, 2025

    Imagen Network to Support Kadena Chainweb EVM for Enhanced Interoperability

    October 23, 2025

    Bitcoin’s institutional surge widens trillion-dollar gap with altcoins

    October 25, 2025

    Bitcoin nears ‘tyranny of numbers’ moment as quantum hardware matures

    December 13, 2025

    UK street gang launders drug funds with memecoin, report

    December 13, 2025

    What If Ethereum Lived on a Treap? Or, Blockchains Charging Rent

    December 13, 2025
    Latest Galleries
    [latest_gallery cat="all" number="5" type="slider"]
    Latest Reviews
    Demo
    Top Posts

    AGII Launches Hybrid Logic Engine to Strengthen Predictive Web3 Infrastructure Control

    December 1, 20251 Views

    AGII Deploys Multi-Threaded Decision Layer to Advance High-Speed Blockchain Intelligence

    November 26, 20251 Views

    AGII Enhances Predictive Intelligence to Strengthen Smart Contract Reliability

    November 19, 20251 Views

    AGII Introduces Multi-Domain Insight Processor to Enhance Analytical Speed Across Web3 Systems

    December 11, 20250 Views
    Don't Miss

    Bitcoin nears ‘tyranny of numbers’ moment as quantum hardware matures

    Crypto December 13, 2025

    Quantum hardware is exiting proof-of-concept, but engineering bottlenecks mean practical, large-scale systems remain decades away.…

    UK street gang launders drug funds with memecoin, report

    December 13, 2025

    What If Ethereum Lived on a Treap? Or, Blockchains Charging Rent

    December 13, 2025

    Bitcoin bulls risk AI-fueled spillover as bubble fears grow at $90k

    December 13, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    Top Posts

    Apex Fusion expands to Base with bAP3X token deployment

    December 3, 20253 Views

    FOIA reveals US Marshals sitting on at least $1.6B in BTC

    December 3, 20253 Views

    Kraken buys Backed Finance, expands tokenized stock platform

    December 3, 20253 Views

    Former OpenSea manager’s insider trading conviction overturned

    December 1, 20253 Views
    Don't Miss

    Bitcoin nears ‘tyranny of numbers’ moment as quantum hardware matures

    Crypto December 13, 2025

    Quantum hardware is exiting proof-of-concept, but engineering bottlenecks mean practical, large-scale systems remain decades away.…

    UK street gang launders drug funds with memecoin, report

    December 13, 2025

    What If Ethereum Lived on a Treap? Or, Blockchains Charging Rent

    December 13, 2025

    Bitcoin bulls risk AI-fueled spillover as bubble fears grow at $90k

    December 13, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    X (Twitter) Instagram YouTube LinkedIn
    Our Picks

    Bitcoin nears ‘tyranny of numbers’ moment as quantum hardware matures

    December 13, 2025

    UK street gang launders drug funds with memecoin, report

    December 13, 2025

    What If Ethereum Lived on a Treap? Or, Blockchains Charging Rent

    December 13, 2025
    Recent Posts
    • Bitcoin nears ‘tyranny of numbers’ moment as quantum hardware matures
    • UK street gang launders drug funds with memecoin, report
    • What If Ethereum Lived on a Treap? Or, Blockchains Charging Rent
    • Bitcoin bulls risk AI-fueled spillover as bubble fears grow at $90k
    • Zora abandons NFTs without warning, launches airdrop with zero rights
    © 2025 - 2026

    Type above and press Enter to search. Press Esc to cancel.