HomeEthereumSecurity Alert –

Security Alert – [Previous security patch can lead to invalid state root on Go clients with a specific transaction sequence – Fixed. Please update.]

-


 

Summary: Implementation bug in the go client may lead to invalid state

Affected client versions: Latest (unpatched) versions of Go client; v1.1.2, v1.0.4 tags and develop, master branches before September 9.

Likelihood: Low

Severity: High

Impact: High

Details: Go ethereum client does not correctly restore state of execution environment when a transaction goes out-of-gas if – within the same block – a contract was suicided. This would result in an invalid copy operation of the state object; flagging the contract as not deleted. This operation would cause a consensus issue between the other implementations.

 

Effects on expected chain reorganisation depth: none

Remedial action taken by Ethereum: Provision of hotfixes as below.

Proposed temporary workaround: Use Python or C++ client

 

If using the PPA: sudo apt-get update then sudo apt-get upgrade

If using brew: brew update then brew reinstall ethereum

If using a windows binary: download the updated binary from https://github.com/ethereum/go-ethereum/releases/tag/v1.1.3

 

Master branch commit: https://github.com/ethereum/go-ethereum/commit/9ebe787d3afe35902a639bf7c1fd68d1e591622a

 

If you’re building from source: git fetch origin && git checkout origin/master followed by a make geth



Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here

LATEST POSTS

Crypto Startups Concerned About Binance Link To Proposed VASP Bill In Kenya

Key TakeawaysKenya’s emerging cryptocurrency sector is facing a regulatory challenge, with concerns growing over the link between cryptocurrency exchanges and a proposed VASP Bill...

Investors Circumvent China’s Crypto Ban by Getting Indirect Exposure Through Stocks

Key TakeawaysChinese crypto investors are using Hong Kong stocks to gain indirect exposure to crypto, therefore circumventing mainland China’s crypto ban.The Guotai Junan International...

Robinhood Cooks With Stock Tokens, Futures, and Its Chain

Key TakeawaysRobinhood unveils tokenized stock assets on the Arbitrum network for its users in the EU and the U.S.Robinhood to allow EU traders access...

Hyra Network Honored as “Technology Startup of the Year” at the 2025 Globee® Awards

Dubai, United Arab Emirates, July 1st, 2025, ChainwireDecentralized AI Framework Gains Recognition for Expanding Access to Compute Power.The digital economy has witnessed transformative platforms...

Most Popular