CRITICAL
GHSA-82vg-5v4f-f9wq
Namada-apps can Crash with Excessive Computation in Mempool Validation
Details
### Impact
A malicious transaction may cause a crash in mempool validation.
A transaction with authorization section containing 256 public keys or more with valid matching signatures triggers an integer overflow in signature verification that causes a the node to panic.
### Patches
This issue has been patched in apps version 1.1.0. The mempool validation has been fixed to avoid overflow.
### Workarounds
There are no workarounds and users are advised to upgrade.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/namada-apps
Introduced in:
1.0.0Fixed in: 1.1.0Upgrade namada-apps to 1.1.0 or newer (ecosystem crates.io).