Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/vulndb: potential Go vuln in github.com/ethereum/go-ethereum: CVE-2021-39137 #254

Closed
GoVulnBot opened this issue Jan 7, 2022 · 1 comment

Comments

@GoVulnBot
Copy link

In CVE-2021-39137, the reference URL github.com/ethereum/go-ethereum (and possibly others) refers to something in Go.

module: github.com/ethereum/go-ethereum
package: go-ethereum
description: |
  go-ethereum is the official Go implementation of the Ethereum protocol. In affected versions a consensus-vulnerability in go-ethereum (Geth) could cause a chain split, where vulnerable versions refuse to accept the canonical chain. Further details about the vulnerability will be disclosed at a later date. A patch is included in the upcoming `v1.10.8` release. No workaround are available.
cves:
- CVE-2021-39137
links:
  context:
  - https://github.com/ethereum/go-ethereum/releases/tag/v1.10.8
  - https://github.com/ethereum/go-ethereum/security/advisories/GHSA-9856-9gg9-qcmq

See doc/triage.md for instructions on how to triage this report.

@gopherbot
Copy link
Contributor

Change https://go.dev/cl/415799 mentions this issue: x/vulndb: add reports/GO-2022-0254.yaml for CVE-2021-39137

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

5 participants