Nixpkgs Security Tracker

Login with GitHub

Details of issue NIXPKGS-2026-0287

NIXPKGS-2026-0287
published on 20 Feb 2026
updated 1 day, 13 hours ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Go Ethereum affected by DoS via malicious p2p message

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, a vulnerable node can be forced to shutdown/crash using a specially crafted message. The problem is resolved in the v1.16.9 and v1.17.0 releases of Geth.

Affected products

go-ethereum
  • ==< 1.16.9

Matching in nixpkgs

Package maintainers

Upstream advisory: https://github.com/ethereum/go-ethereum/security/advisories/GHSA-2gjw-fg97-vg3r
Upstream patch: https://github.com/ethereum/go-ethereum/commit/895a8597cb16c02203e38707ed2d1da5c500fe60