Loading...
The Ethereum client Besu released version 26.7.1 on July 27th, fixing 5 security vulnerabilities discovered by CertiK, and released 4 security notices on August 14th. Jialiang Chang, Director of Security Engineering and Senior Audit Partner at CertiK, stated that the patch first and detail later arrangements provide an 18 day buffer period, allowing node operators to identify affected deployments, test new versions, and complete upgrades. The vulnerabilities involve block broadcast processing, caching of future high consensus proposals, WebSocket subscription restrictions, and creation of JSON-RPC filters. CertiK conducts adversarial testing in a private testing network using Chain Scan method and provides reproducible testing tools to the Besu team. CertiK is updating Chain Scan for 24/7 multi node testing. (Bitcoin.com News)