A vulnerability in the Geth EVM can cause a node to reject the canonical chain.
A memory-corruption bug within the EVM can cause a consensus error, where vulnerable nodes obtain a different stateRoot when processing a maliciously crafted transaction. This, in turn, would lead to the chain being split in two forks.
{
    "url": "https://pkg.go.dev/vuln/GO-2022-0254",
    "review_status": "REVIEWED"
}