Affected Clients | UID | Bug | Type | Links | Reported | Fixed Date | Published | Severity | CVE | Bounty Hunter | Bounty Points | Bounty Reward (USD) |
---|---|---|---|---|---|---|---|---|---|---|---|---|
None | EL-2021-14 | Elliptic curve crash with invalid point | Crypto | golang/go#50974 | 2021-12-19 | 2022-02-02 | 2023-05-03 | Low | CVE-2022-23806 | Guido Vranken | 100 | 200 |
None | EL-2022-01 | mcl: FpToG1/Fp2ToG2 incorrect result | Crypto | https://notes.ethereum.org/EqjqEMRRSjKEHVpzbd5HCg | 2022-01-30 | 2022-01-30 | 2023-05-03 | Low | Guido Vranken | 250 | 500 | |
None | EL-2022-02 | Golang: Point scalar multiplication results in point at infinity | golang/go#58647 | 2022-02-22 | 2022-03-07 | 2023-05-03 | Low | CVE-2023-24532 | Guido Vranken | 250 | 500 | |
Solidity | EL-2022-03 | Calldata validation bug | Solidity | https://notes.ethereum.org/f4o4dzdLS2-re85X3c9Pvw | 2022-04-17 | 2022-04-17 | 2023-05-03 | Low | John Toman | 500 | 1000 | |
Geth | EL-2022-04 | DoS via malicious p2p message | DoS | https://github.com/ethereum/go-ethereum/security/advisories/GHSA-wjxw-gh3m-7pm5 | 2022-05-01 | 2022-05-11 | 2023-05-03 | Low | CVE-2022-29177 | nrv | Donated to Medecins sans frontieres | |
Solidity | EL-2022-05 | The solidity optimizer incorrectly removes memory writes that affect global state | Solidity | https://notes.ethereum.org/zOAIzbDeSvWXuCw7bnEocw | 2022-06-14 | 2022-06-20 | 2023-05-03 | Medium | John Toman | 5000 | 10000 | |
Nethermind | EL-2022-06 | modexp gas calculation consensus bug | Consensus | https://notes.ethereum.org/SMlCIdivQsCbMcyfORoLng | 2022-06-22 | 2022-06-30 | 2023-05-03 | Medium | Alex Beregszaszi | 3500 | 0 (EF) | |
Besu, Geth | EL-2022-07 | modular exponentiation with specific parameters is too slow and can introduce a DoS vector in specific cases. | DoS | https://go-review.googlesource.com/c/go/+/420897 | 2022-07-04 | 2022-11-02 | 2023-05-03 | Medium | Guido Vranken | 3250 | 7500 | |
Geth | EL-2022-08 | Partitioning Ethereum without Eclipsing It | Consensus | https://notes.ethereum.org/sBWuEgDzRei8XjVR48EzKg | 2022-07-31 | 2022-08-31 | 2023-05-03 | Low | Hwanjo Heo | 1000 | 2000 | |
Erigon | EL-2022-09 | Consensus flaw during block processing | Consensus | https://github.com/advisories/GHSA-xw37-57qp-9mm4 | 2022-08-23 | 2023-02-28 | 2023-05-03 | Medium | CVE-2020-26265 | kismp123 | 5000 | 10000 |
Nethermind | EL-2022-10 | SMOD consensus flaw in Nethermind | Consensus | https://notes.ethereum.org/lzl_2mBPTimS9PjkWZMW9w | 2022-09-01 | 2022-09-03 | 2023-05-03 | Medium | PwningEth | 5000 | 10000 (Donated to charity) | |
Besu | EL-2022-11 | Slow transaction verification on Besu client | DoS | https://notes.ethereum.org/zSE44ueJS9-_G7lOzPalEQ | 2022-09-12 | 2022-09-14 | 2023-05-03 | Medium | ChainSecurity | 2000 | 4000 | |
Geth | EL-2022-12 | DETER-X attack | DoS | https://drive.google.com/file/d/1nVt05wHMr8Ls2zsUg77lW0VqxcfudYWp/view?usp=share_link | 2022-09-14 | 2022-12-31 | 2023-05-03 | Low | Team Bob Conan | 1000 | 2000 | |
Nethermind | EL-2022-13 | Nethermind ModExp Consensus Failure (OutOfMemory Exception) | Consensus | https://gist.github.com/pleasew8t/734fb76304bf8375b60cfc9b46cc9351 | 2022-10-14 | 2022-10-17 | 2023-05-03 | Medium | https://iosiro.com/ | 5000 | 10000 | |
Besu | EL-2022-14 | Raises exception leading to chain split | Consensus | https://notes.ethereum.org/d6BISTgxSV-_xIeBuGrV9A | 2022-11-20 | 2022-10-31 | 2023-05-03 | Medium | Guido Vranken | 5000 | 20000 | |
Besu | EL-2022-15 | Slow input (16s) | DoS | https://notes.ethereum.org/N9akOoR-Rn2Ad4P6S032Bg | 2022-11-20 | 2022-11-23 | 2023-05-03 | Medium | Guido Vranken | 2000 | 4000 | |
Nethermind | EL-2022-16 | Slow input (6s) | DoS | https://notes.ethereum.org/gdNfvyntQbu5rU6D97yMQg | 2022-11-28 | 2022-12-01 | 2023-05-03 | Low | Guido Vranken | 500 | 1000 | |
Besu | EL-2022-17 | Very slow block execution | DoS | https://gist.github.com/holiman/213cc1a59971279bc984e2957c089af2#file-writeup-md | 2022-11-30 | 2022-12-01 | 2023-05-03 | Medium | Martin Swende | 2000 | 0 (EF) |