VDB
Sign up
CRITICAL

GHSA-82vg-5v4f-f9wq

Namada-apps can Crash with Excessive Computation in Mempool Validation

Details

### Impact

A malicious transaction may cause a crash in mempool validation.

A transaction with authorization section containing 256 public keys or more with valid matching signatures triggers an integer overflow in signature verification that causes a the node to panic.

### Patches

This issue has been patched in apps version 1.1.0. The mempool validation has been fixed to avoid overflow.

### Workarounds

There are no workarounds and users are advised to upgrade.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/namada-apps
Introduced in: 1.0.0Fixed in: 1.1.0

Upgrade namada-apps to 1.1.0 or newer (ecosystem crates.io).

References