{"schema_version":"1.7.3","id":"GHSA-q26p-9cq4-7fc2","published":"2025-01-30T17:51:57Z","modified":"2025-03-17T20:25:21Z","aliases":["CVE-2025-24883","GO-2025-3436"],"summary":"Go Ethereum vulnerable to DoS via malicious p2p message","details":"### Impact\n\nA vulnerable node can be forced to shutdown/crash using a specially crafted message.\n\nDuring the peer-to-peer connection handshake, a shared secret key is computed. The implementation\ndid not verify whether the EC public key provided by the remote party is a valid point on the secp256k1 curve.\nBy simply sending an all-zero public key, a crash could be induced due to unexpected results from the handshake.\n\nThe issue was fixed by adding a curve point validity check in https://github.com/ethereum/go-ethereum/commit/159fb1a1db551c544978dc16a5568a4730b4abf3\n\n### Patches\n\nA fix has been included in geth version 1.14.13 and onwards.\n\n### Workarounds\n\nUnfortunately, no workaround is available.\n\n### Credits\n\nThis issue was originally reported to Polygon Security by David Matosse (@iam-ned).","affected":[{"package":{"name":"github.com/ethereum/go-ethereum","ecosystem":"Go","purl":"pkg:golang/github.com/ethereum/go-ethereum"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.14.0"},{"fixed":"1.14.13"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/01/GHSA-q26p-9cq4-7fc2/GHSA-q26p-9cq4-7fc2.json"}}],"references":[{"type":"WEB","url":"https://github.com/ethereum/go-ethereum/security/advisories/GHSA-q26p-9cq4-7fc2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-24883"},{"type":"WEB","url":"https://github.com/ethereum/go-ethereum/commit/159fb1a1db551c544978dc16a5568a4730b4abf3"},{"type":"WEB","url":"https://github.com/ethereum/go-ethereum/commit/fa9a2ff8687ec9efe57b4b9833d5590d20f8a83f"},{"type":"PACKAGE","url":"https://github.com/ethereum/go-ethereum"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2025-3436"}],"database_specific":{"cwe_ids":["CWE-20","CWE-248"],"github_reviewed":true,"github_reviewed_at":"2025-01-30T17:51:57Z","nvd_published_at":"2025-01-30T16:15:31Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U"}]}