CVE-2024-32972

high

Description

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to 1.13.15, a vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. The fix has been included in geth version `1.13.15` and onwards.

References

https://github.com/ethereum/go-ethereum/security/advisories/GHSA-4xc9-8hmq-j652

https://github.com/ethereum/go-ethereum/compare/v1.13.14...v1.13.15

Details

Source: Mitre, NVD

Published: 2024-05-06

Updated: 2024-05-06

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity: High