Besu fixes 5 security vulnerabilities, version 26.7.1 released on July 27
Odaily Planet Daily News Ethereum client Besu has fixed 5 security vulnerabilities discovered by blockchain security company CertiK in version 26.7.1, released on July 27, and published 4 detailed security advisories on August 14. Vulnerability details were disclosed later to allow node operators time to complete upgrade deployments.
CertiK's Director of Security Engineering and Senior Audit Partner Jialiang Chang stated that the arrangement of releasing patches first and details later provided an 18-day buffer period, allowing node operators to identify affected deployments, test new versions, and coordinate with validators or consortium participants to complete upgrades.
The related vulnerabilities involve block broadcast processing, future height consensus proposal caching, WebSocket subscription limits, and JSON-RPC filter creation. If left unpatched, attackers could exhaust node memory or thread resources, affecting node availability and consensus processing.
CertiK used the Chain Scan methodology to conduct adversarial testing on peer-to-peer, HTTP RPC, WebSocket RPC, and consensus interfaces in a private multi-node test network, and provided reproducible testing tools to the Besu team. CertiK is updating Chain Scan to expand round-the-clock multi-node testing of public chain networks. (Bitcoin.com News)
