Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update: Go-Ethereum vulnerable to denial of service via malicious p2p message #754

Closed
taariq opened this issue Sep 6, 2023 · 3 comments
Closed
Assignees
Labels
enhancement New feature or request

Comments

@taariq
Copy link
Member

taariq commented Sep 6, 2023

3 repositories in your palomachain organization might be affected by a security vulnerability.
https://github.com/advisories/GHSA-ppjg-v974-84cm/dependabot?query=user:palomachain

@taariq taariq added the enhancement New feature or request label Sep 6, 2023
@byte-bandit
Copy link

As discussed, we're not a direct consumer of go-ethereum any longer.

At the moment, we rely mostly on

  • op-geth which forks go-ethereum one way
  • arb-geth, which forks it the other way

At the moment, the Arbitrum fork has merged in the changes for 1.12.0 only, 1.12.1 is still outstanding: OffchainLabs/go-ethereum#248

The same goes for Optimism, which is also stuck as 1.12.0 with no indicator of 1.12.1 on the horizon: ethereum-optimism/op-geth#104

This means we're effectively blocked until both teams update their library to include the changes from 1.12.1 of go-ethereum.

@taariq
Copy link
Member Author

taariq commented Sep 7, 2023

Closing until our upstream partners release.

@taariq taariq closed this as completed Sep 7, 2023
@byte-bandit
Copy link

@taariq Let's capture this as something to revisit in the future somewhere, I don't want to lose sight of it until it's too late.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants