go-ethereum v1.17.8 security release fixes p2p DoS issues and a STUN-response node crash
go-ethereum (Geth) v1.17.8 is a security-focused release fixing several denial-of-service risks in the eth/snap p2p handlers, JUMPDEST analysis caching, BAL account handling, and a crash triggered by a rogue STUN server. Most fixes concern post-Amsterdam behaviour. Node operators should upgrade to v1.17.8.
Vuln-watch · relayed from an upstream security release; see Source & attribution below
Summary
go-ethereum v1.17.8 is described by the Geth team as a security-focused release fixing several DoS risk issues. According to the release notes, most of the fixes relate to bugs that only become possible after activation of the Amsterdam fork. The release also includes general correctness improvements and is recommended for all users.
Affected
- go-ethereum (Geth) prior to v1.17.8
- Fixed in v1.17.8
Impact
Per the release notes: - eth and snap p2p protocol handlers: DoS resistance improved for multiple packet handlers (#35862, #35883, #35859, #35857, #35904, #35856). - JUMPDEST analysis caching hardened for attack cases after the Amsterdam fork (#35881). - The IP address predictor now requires IP verification before accepting statements (#35861). - A post-Amsterdam DoS vector related to BAL accounts is resolved (#35865). - A rogue STUN server could crash the node with an invalid response (#35863). No CVE or GHSA identifier is listed and the release notes do not report exploitation in the wild.
Recommended actions
- Upgrade Geth nodes to v1.17.8, in particular before the Amsterdam fork activates on networks you operate.
- Track the go-ethereum security advisories page for any follow-up CVE/GHSA assignments.
Source & attribution
This 0xCERT advisory summarises a disclosure by the go-ethereum team in the v1.17.8 release notes: https://github.com/ethereum/go-ethereum/releases/tag/v1.17.8. Details may change; refer to the original source for the authoritative record.
References
OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.
Published 2026-10-08 · last updated 2026-10-08
curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0163/signed.txt | gpg --verify