{"id":"CVE-2020-26241","aliases":["GHSA-69v6-xc2j-r2jf","GO-2022-0771"],"title":"Shallow copy bug in geth","summary":"Shallow copy bug in geth","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","vendor":"ethereum","product":"github.com/ethereum/go-ethereum","ecosystem":"go","affected":["github.com/ethereum/go-ethereum >= 1.9.7, < 1.9.17"],"patched":["github.com/ethereum/go-ethereum 1.9.17"],"published":"2021-06-29","updated":"2026-07-08","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-69v6-xc2j-r2jf","references":[{"url":"https://github.com/ethereum/go-ethereum/security/advisories/GHSA-69v6-xc2j-r2jf"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-26241"},{"url":"https://github.com/ethereum/go-ethereum/commit/295693759e5ded05fec0b2fb39359965b60da785"},{"url":"https://blog.ethereum.org/2020/11/12/geth_security_release"},{"url":"https://github.com/ethereum/go-ethereum"}],"tags":["osv","go"],"epss":0.01226,"epssPercentile":0.67554,"ingestedAt":"2026-07-09T18:56:35.980Z","slug":"CVE-2020-26241","body":"## Overview\n\n### Impact\nThis is a Consensus vulnerability, which can be used to cause a chain-split where vulnerable nodes reject the canonical chain. \n\nGeth’s pre-compiled `dataCopy` (at `0x00...04`) contract did a shallow copy on invocation. An attacker could deploy a contract that \n\n- writes `X` to an EVM memory region `R`,\n- calls `0x00..04` with `R` as an argument,\n- overwrites `R` to `Y`,\n- and finally invokes the `RETURNDATACOPY` opcode.\n\nWhen this contract is invoked, a consensus-compliant node would push `X` on the EVM stack, whereas Geth would push `Y`.\n\n\n### Patches\n\nNo standalone patches have been made. \n\n### Workarounds\n\nUpgrade to `1.9.17` or higher.\n\n### References\n\nhttps://blog.ethereum.org/2020/11/12/geth_security_release/\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [go-ethereum](https://github.com/ethereum/go-ethereum)\n* Email us at [security@ethereum.org](mailto:security@ethereum.org)\n\n\n## Affected packages\n\n- `github.com/ethereum/go-ethereum >= 1.9.7, < 1.9.17`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/ethereum/go-ethereum 1.9.17`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}