-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 0xCERT Security Advisory 0xCERT-2026-0165 ============================================================ Advisory-ID: 0xCERT-2026-0165 Severity: Medium Published: 2026-09-09T20:41:51.000Z Updated: 2026-10-08T22:46:34.048Z Chains: Ethereum URL: https://www.0xcert.com/advisory/0xCERT-2026-0165 Title: Erigon v3.6.1: security release for Ethereum node operators Summary - ------- Erigon v3.6.1 (released 2026-09-09) includes security fixes according to its release notes. Ethereum node operators running Erigon should review and upgrade. Details - ------- Summary Erigon v3.6.1 (released 2026-09-09) includes security fixes according to its release notes. Ethereum node operators running Erigon should review and upgrade. Affected - - Erigon (erigontech/erigon) versions before v3.6.1 From the release notes ## Erigon v3.6.1 — Upstream Underbelly v3.6.1 is a bugfix and security release recommended for all users. It fixes a downloader regression that could silently replace a valid local snapshot (#23859), a peer-ban bypass that let a banned Caplin peer reconnect immediately (#23866), an index-build defect that could leave stale bits in a recsplit index after a salt-collision retry (#23858), and bumps google.golang.org/grpc for two HIGH-severity CVEs (#23888). It is a drop-in upgrade from 3.6.0 — no re-sync required. ## Highlights - - db/downloader: keep local snapshot data once the initial download is complete (#23859) by @AskAlexSharov — a locally-differing .seg that no longer matched its .torrent was silently replaced even after preverified.toml existed; it is now kept and registered for seeding, with a warn-level log when a mismatched file is still replaced. Fixes #21522. - - cl/sentinel: Recommended actions - - Upgrade Erigon to v3.6.1 or later - - Check the release notes for any coordinated upgrade deadline or required configuration change Source & attribution This 0xCERT advisory relays the Erigon v3.6.1 release notes: https://github.com/erigontech/erigon/releases/tag/v3.6.1. Refer to the upstream project for the authoritative record and any follow-up security advisories. References - ---------- - - https://github.com/erigontech/erigon/releases/tag/v3.6.1 - - CVE-2026-84304 - - CVE-2026-84445 Verify with the 0xCERT OpenPGP key: https://www.0xcert.com/pgp.asc Fingerprint: 5F94 3ED1 1E50 CF31 2128 C493 CCC7 D9EC 9415 723D -----BEGIN PGP SIGNATURE----- wrsEARYKAG0FgmrIRjoJEDe9Tbcr+ZxrRRQAAAAAABwAIHNhbHRAbm90YXRp b25zLm9wZW5wZ3Bqcy5vcmescNLjm5T7APD9+B4zHcQwW1cj4XNCupZzjwkF p0lTcRYhBGCkkFZbJcT5QWu27ze9Tbcr+ZxrAABFpgD/Q0ypyzrZgv7IJoPD yrrAS5I3B6ZmWdeax9pQleRPtBsBAKAGZObQrOHGZuxODgolf5y96LBQ7bJi Al/uPLD/q8UI =+lJ3 -----END PGP SIGNATURE-----