NRDAX-T0214 - Protocol Message Flood Unbounded Goroutine
Connection exhaustion (also memory amplification) · P2P and gossip · no bound · active · first seen 2023-01-01
provenance: Reproduced in NullRabbit's attack-reproduction pipeline
mechanism
CVE-2023-40591: post-Hello devp2p PING (0x02) flood → unbounded goroutines → OOM (geth 1.10.0-1.12.0)
live exposure
No exposure data. Slashr ↗ has no risk signal mapped to this technique yet — absence of data is not absence of exposure.
instances (1)
| chain | primitive | fidelity | origin | reproducer (bundle) | source |
|---|---|---|---|---|---|
| ethereum | geth_devp2p_ping_flood | lab | reverse-engineered-cve | geth_devp2p_ping_flood | GHSA-ppjg-v974-84cm ↗ |
references
cve: CVE-2023-40591
related (Connection exhaustion)
NRDAX-T0041 - Cross-Chain Peer Pool Pollution active NRDAX-T0064 - Endpoint Concurrency Cap Exhaustion active NRDAX-T0099 - Half-Open Handshake Slowloris active NRDAX-T0225 - QUIC Control Frame Flood active NRDAX-T0246 - Rate-Limit Key Confusion active NRDAX-T0261 - RPC Request Flood active NRDAX-T0291 - Subscription Permit Exhaustion active NRDAX-T0320 - Unbounded Connection Flood active
cite
https://nrdax.com/techniques/NRDAX-T0214
plain
NRDAX Registry. Technique NRDAX-T0214.
bibtex
@misc{nrdax_NRDAX_T0214,
title = {Protocol Message Flood Unbounded Goroutine (NRDAX-T0214)},
howpublished = {NRDAX Registry},
url = {https://nrdax.com/techniques/NRDAX-T0214},
} json (csl)
{
"id": "nrdax-NRDAX-T0214",
"type": "dataset",
"title": "Protocol Message Flood Unbounded Goroutine (NRDAX-T0214)",
"URL": "https://nrdax.com/techniques/NRDAX-T0214",
"publisher": "NRDAX Registry"
} badge
[](https://nrdax.com/techniques/NRDAX-T0214-protocol-message-flood-unbounded-goroutine)
use from the CLI
Retrieve or cite this technique from a script or the terminal with the NRDAX Python library & CLI.
nrdax get NRDAX-T0214 nrdax cite NRDAX-T0214 --format bibtex