Skip to content

x/vulndb: potential Go vuln in github.com/ethereum/go-ethereum/consensus: GHSA-v592-xf75-856p #1436

New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Closed
GoVulnBot opened this issue Jan 9, 2023 · 1 comment

Comments

@GoVulnBot
Copy link

In GitHub Security Advisory GHSA-v592-xf75-856p, there is a vulnerability in the following Go packages or modules:

Unit Fixed Vulnerable Ranges
github.com/ethereum/go-ethereum/consensus 1.9.24 < 1.9.24

Cross references:

See doc/triage.md for instructions on how to triage this report.

modules:
  - module: TODO
    versions:
      - fixed: 1.9.24
    packages:
      - package: github.com/ethereum/go-ethereum/consensus
  - module: TODO
    versions:
      - fixed: 1.9.24
    packages:
      - package: github.com/ethereum/go-ethereum
description: "### Impact\nAn ethash mining DAG generation flaw in Geth could cause
    miners to erroneously calculate PoW in an upcoming epoch (estimated early January,
    2021). This happened on the ETC chain on 2020-11-06. This issue is relevant only
    for miners, non-mining nodes are unaffected.\n\n### Patches\nThis issue is also
    fixed as of 1.9.24. Thanks to @slavikus for bringing the issue to our attention
    and writing the fix. \n\n### For more information\nIf you have any questions or
    comments about this advisory:\n* Open an issue in [go-ethereum](https://github.com/ethereum/go-ethereum)\n*
    Email us at [security@ethereum.org](mailto:security@ethereum.org)"
cves:
  - CVE-2020-26240
ghsas:
  - GHSA-v592-xf75-856p

@tatianab
Copy link
Contributor

tatianab commented Jan 9, 2023

Duplicate of #775

# for free to join this conversation on GitHub. Already have an account? # to comment
Projects
None yet
Development

No branches or pull requests

2 participants