Loading...
Besu fixes 5 security vulnerabilities, version 26.7.1 was released on July 27th Odaily Planet Daily News: Ethereum client Besu has fixed 5 security vulnerabilities discovered by blockchain security company CertiK in version 26.7.1 released on July 27th, and released 4 detailed security notices on August 14th. The details of the vulnerability will be delayed for node operators to complete the upgrade and deployment. Jialiang Chang, Director of Security Engineering and Senior Audit Partner at CertiK, stated that the patch first and detail later arrangements provide an 18 day buffer period. Node operators can identify affected deployments, test new versions, and coordinate validators or alliance participants to complete the upgrade. The related vulnerabilities involve block broadcast processing, caching of future high consensus proposals, WebSocket subscription restrictions, and creation of JSON-RPC filters. If not fixed, attackers may exhaust node memory or thread resources, affecting node availability and consensus processing. CertiK conducts adversarial testing on peer-to-peer, HTTP RPC, WebSocket RPC, and consensus interfaces in a private multi node testing network using Chain Scan method, and provides reproducible testing tools to the Besu team. CertiK is updating Chain Scan to expand 24/7 multi node testing of public chain networks. ((Bitcoin.com) News)