---
id: CVE-2020-26241
aliases:
  - GHSA-69v6-xc2j-r2jf
  - GO-2022-0771
title: Shallow copy bug in geth
summary: Shallow copy bug in geth
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'
vendor: ethereum
product: github.com/ethereum/go-ethereum
ecosystem: go
affected:
  - 'github.com/ethereum/go-ethereum >= 1.9.7, < 1.9.17'
patched:
  - github.com/ethereum/go-ethereum 1.9.17
published: '2021-06-29'
updated: '2026-07-08'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-69v6-xc2j-r2jf'
references:
  - url: >-
      https://github.com/ethereum/go-ethereum/security/advisories/GHSA-69v6-xc2j-r2jf
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2020-26241'
  - url: >-
      https://github.com/ethereum/go-ethereum/commit/295693759e5ded05fec0b2fb39359965b60da785
  - url: 'https://blog.ethereum.org/2020/11/12/geth_security_release'
  - url: 'https://github.com/ethereum/go-ethereum'
tags:
  - osv
  - go
epss: 0.01226
epssPercentile: 0.67629
ingestedAt: '2026-07-09T18:56:35.980Z'
---

## Overview

### Impact
This is a Consensus vulnerability, which can be used to cause a chain-split where vulnerable nodes reject the canonical chain. 

Geth’s pre-compiled `dataCopy` (at `0x00...04`) contract did a shallow copy on invocation. An attacker could deploy a contract that 

- writes `X` to an EVM memory region `R`,
- calls `0x00..04` with `R` as an argument,
- overwrites `R` to `Y`,
- and finally invokes the `RETURNDATACOPY` opcode.

When this contract is invoked, a consensus-compliant node would push `X` on the EVM stack, whereas Geth would push `Y`.


### Patches

No standalone patches have been made. 

### Workarounds

Upgrade to `1.9.17` or higher.

### References

https://blog.ethereum.org/2020/11/12/geth_security_release/

### For more information
If you have any questions or comments about this advisory:
* Open an issue in [go-ethereum](https://github.com/ethereum/go-ethereum)
* Email us at [security@ethereum.org](mailto:security@ethereum.org)


## Affected packages

- `github.com/ethereum/go-ethereum >= 1.9.7, < 1.9.17`

## Remediation

Upgrade to a patched release:

- `github.com/ethereum/go-ethereum 1.9.17`
