CVE-2024-32972

HIGH

go-ethereum < 1.13.15 - Uncontrolled Resource Consumption via P2P Message Handling

Title source: llm
STIX 2.1

Description

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to 1.13.15, a vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. The fix has been included in geth version `1.13.15` and onwards.

References (2)

Core 2

Scores

CVSS v3 7.5
EPSS 0.0085
EPSS Percentile 53.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (2)
ethereum/go-ethereum 0 - 1.13.15Go
ethereum/go-ethereum < 1.13.15
Published May 06, 2024
Tracked Since Feb 18, 2026