Skip to content

x/vulndb: potential Go vuln in github.com/ethereum/go-ethereum: CVE-2025-24883 #3436

New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Closed
GoVulnBot opened this issue Jan 30, 2025 · 1 comment

Comments

@GoVulnBot
Copy link

Advisory CVE-2025-24883 references a vulnerability in the following Go modules:

Module
github.com/ethereum/go-ethereum

Description:
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdown/crash using a specially crafted message. This vulnerability is fixed in 1.14.13.

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/ethereum/go-ethereum
      vulnerable_at: 1.14.13
summary: CVE-2025-24883 in github.com/ethereum/go-ethereum
cves:
    - CVE-2025-24883
references:
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-24883
    - fix: https://github.com/ethereum/go-ethereum/commit/fa9a2ff8687ec9efe57b4b9833d5590d20f8a83f
    - web: https://github.com/ethereum/go-ethereum/security/advisories/GHSA-q26p-9cq4-7fc2
source:
    id: CVE-2025-24883
    created: 2025-01-30T17:01:25.162446187Z
review_status: UNREVIEWED

@gopherbot
Copy link
Contributor

Change https://go.dev/cl/646595 mentions this issue: data/reports: add 9 unreviewed reports

# for free to join this conversation on GitHub. Already have an account? # to comment
Projects
None yet
Development

No branches or pull requests

3 participants