Skip to content

Ethash DAG generation bug can cause miners to create invalid PoW

Moderate
holiman published GHSA-v592-xf75-856p Nov 24, 2020

Package

go-ethereum (golang)

Affected versions

<1.9.24

Patched versions

1.9.24

Description

Impact

An ethash mining DAG generation flaw in Geth could cause miners to erroneously calculate PoW in an upcoming epoch (estimated early January, 2021). This happened on the ETC chain on 2020-11-06. This issue is relevant only for miners, non-mining nodes are unaffected.

Patches

This issue is also fixed as of 1.9.24. Thanks to @slavikus for bringing the issue to our attention and writing the fix.

Workarounds

This PR implements a patch: #21793

References

https://blog.ethereum.org/2020/11/12/geth_security_release/

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

CVE-2020-26240

Weaknesses

No CWEs

Credits