-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 0xCERT Security Advisory 0xCERT-2026-0163 ============================================================ Advisory-ID: 0xCERT-2026-0163 Severity: High Published: 2026-10-08T16:35:00.000Z Updated: 2026-10-08T20:36:48.066Z Chains: Ethereum URL: https://www.0xcert.com/advisory/0xCERT-2026-0163 Title: go-ethereum v1.17.8 security release fixes p2p DoS issues and a STUN-response node crash Summary - ------- go-ethereum (Geth) v1.17.8 is a security-focused release fixing several denial-of-service risks in the eth/snap p2p handlers, JUMPDEST analysis caching, BAL account handling, and a crash triggered by a rogue STUN server. Most fixes concern post-Amsterdam behaviour. Node operators should upgrade to v1.17.8. Details - ------- Summary go-ethereum v1.17.8 is described by the Geth team as a security-focused release fixing several DoS risk issues. According to the release notes, most of the fixes relate to bugs that only become possible after activation of the Amsterdam fork. The release also includes general correctness improvements and is recommended for all users. Affected - - go-ethereum (Geth) prior to v1.17.8 - - Fixed in v1.17.8 Impact Per the release notes: - - eth and snap p2p protocol handlers: DoS resistance improved for multiple packet handlers (#35862, #35883, #35859, #35857, #35904, #35856). - - JUMPDEST analysis caching hardened for attack cases after the Amsterdam fork (#35881). - - The IP address predictor now requires IP verification before accepting statements (#35861). - - A post-Amsterdam DoS vector related to BAL accounts is resolved (#35865). - - A rogue STUN server could crash the node with an invalid response (#35863). No CVE or GHSA identifier is listed and the release notes do not report exploitation in the wild. Recommended actions - - Upgrade Geth nodes to v1.17.8, in particular before the Amsterdam fork activates on networks you operate. - - Track the go-ethereum security advisories page for any follow-up CVE/GHSA assignments. Source & attribution This 0xCERT advisory summarises a disclosure by the go-ethereum team in the v1.17.8 release notes: https://github.com/ethereum/go-ethereum/releases/tag/v1.17.8. Details may change; refer to the original source for the authoritative record. References - ---------- - - https://github.com/ethereum/go-ethereum/releases/tag/v1.17.8 - - https://github.com/ethereum/go-ethereum/pull/35863 - - https://github.com/ethereum/go-ethereum/pull/35865 - - https://github.com/ethereum/go-ethereum/pull/35881 Verify with the 0xCERT OpenPGP key: https://www.0xcert.com/pgp.asc Fingerprint: 5F94 3ED1 1E50 CF31 2128 C493 CCC7 D9EC 9415 723D -----BEGIN PGP SIGNATURE----- wrsEARYKAG0FgmrILuUJEDe9Tbcr+ZxrRRQAAAAAABwAIHNhbHRAbm90YXRp b25zLm9wZW5wZ3Bqcy5vcmdNZ3CJKun7OA4UXJUpLd38+kne3/AlRpi/Z+d+ V3dOmRYhBGCkkFZbJcT5QWu27ze9Tbcr+ZxrAACRQQD/Q5L6fIFAHeCNd1+3 qGcz/aDv3tvO8ciLaAB6oVMyJbMBANIGIHN1znrFkAFOhNSZGEBFCrrLo89b 1mUTQs/DxnwN =xtP0 -----END PGP SIGNATURE-----