CVE-2020-26240
Erroneous Proof of Work calculation in geth
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. An ethash mining DAG generation flaw in Geth before version 1.9.24 could cause miners to erroneously calculate PoW in an upcoming epoch (estimated early January, 2021). This happened on the ETC chain on 2020-11-06. This issue is relevant only for miners, non-mining nodes are unaffected. This issue is fixed as of 1.9.24
Go Ethereum, o "Geth", es la implementación oficial de Golang del protocolo Ethereum. Un fallo de generación DAG de minería ethash en Geth versiones anteriores a 1.9.24, podría causar a unos mineros calcular erróneamente PoW en una época próxima (estimada a principios de enero de 2021). Esto sucedió en la cadena ETC el 06-11-2020. Este problema es relevante solo para mineros, los nodos que no son mineros no están afectados. Este problema es corregido desde la versión 1.9.24
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-10-01 CVE Reserved
- 2020-11-25 CVE Published
- 2024-08-04 CVE Updated
- 2024-09-29 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-682: Incorrect Calculation
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/ethereum/go-ethereum/security/advisories/GHSA-v592-xf75-856p | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/ethereum/go-ethereum/commit/d990df909d7839640143344e79356754384dcdd0 | 2020-12-03 | |
https://github.com/ethereum/go-ethereum/pull/21793 | 2020-12-03 |
URL | Date | SRC |
---|---|---|
https://blog.ethereum.org/2020/11/12/geth_security_release | 2020-12-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ethereum Search vendor "Ethereum" | Go Ethereum Search vendor "Ethereum" for product "Go Ethereum" | < 1.9.24 Search vendor "Ethereum" for product "Go Ethereum" and version " < 1.9.24" | - |
Affected
|