CVE-2021-43668
Ethereum Geth vulnerability analysis and mitigation

Overview

Go-Ethereum (geth) version 1.10.9 was discovered to be vulnerable to a denial of service attack where nodes would crash after receiving a series of specially crafted messages and could not be recovered. The vulnerability was disclosed on November 8, 2021, affecting nodes running in fast sync mode (GitHub Issue).

Technical details

The vulnerability manifests as a runtime error with the message "invalid memory address or nil pointer dereference" which triggers a SEGV signal. The crash occurs in the goleveldb component when handling certain p2p messages. According to the CVSS 3.1 scoring, this vulnerability has a base score of 5.5 (Medium) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (NVD).

Impact

When successfully exploited, the vulnerability causes affected nodes to crash and become unrecoverable, leading to a denial of service condition. This particularly impacts nodes running in fast sync mode, potentially disrupting network operations and blockchain synchronization (GitHub Issue).

Mitigation and workarounds

The vulnerability was addressed in subsequent versions of go-ethereum. Users running affected versions (1.10.9) should upgrade to a patched version to prevent potential exploitation (NVD).

Additional resources


SourceThis report was generated using AI

Related Ethereum Geth vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-24883HIGH8.7
  • Ethereum GethEthereum Geth
  • github.com/ethereum/go-ethereum
NoYesJan 30, 2025
CVE-2024-32972HIGH7.5
  • Ethereum GethEthereum Geth
  • cpe:2.3:a:ethereum:go_ethereum
NoYesMay 06, 2024
CVE-2023-42319HIGH7.5
  • Ethereum GethEthereum Geth
  • cpe:2.3:a:ethereum:go_ethereum
NoYesOct 18, 2023
CVE-2023-40591HIGH7.5
  • Ethereum GethEthereum Geth
  • github.com/ethereum/go-ethereum
NoYesSep 06, 2023
CVE-2022-37450MEDIUM5.9
  • Ethereum GethEthereum Geth
  • geth
NoYesAug 05, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management