GHSA-mx2j-7cmv-353c
wasmvm: Malicious smart contract can slow down block production
Quick fix
GHSA-mx2j-7cmv-353c — github.com/CosmWasm/wasmvm: upgrade to the fixed version with the command below.
go get github.com/CosmWasm/wasmvm@v1.5.8Details
# CWA-2025-002
**Severity**
Medium (Moderate + Likely)[^1]
**Affected versions:**
- wasmvm >= 2.2.0, < 2.2.2 - wasmvm >= 2.1.0, < 2.1.5 - wasmvm >= 2.0.0, < 2.0.6 - wasmvm < 1.5.8
**Patched versions:**
- wasmvm 1.5.8, 2.0.6, 2.1.5, 2.2.2
## Description of the bug
The vulnerability can be used to slow down block production. The attack requires a malicious contract, so permissioned chains are unlikely to be affected.
(We'll add more detail once chains had a chance to upgrade.)
## Patch
- 1.5: https://github.com/CosmWasm/cosmwasm/commit/2b7f2faa57a1efc8207455c37f87f1eee6035a27 - 2.0: https://github.com/CosmWasm/cosmwasm/commit/d6143b0aff16a39bbea4be37597d8e9d9b213d3b - 2.1: https://github.com/CosmWasm/cosmwasm/commit/f0c04c03cbe2557634c1bbcdc2ce203fe7caca58 - 2.2: https://github.com/CosmWasm/cosmwasm/commit/a5d62f65b5eb947ebe40e2085b1c48a9d0a244d0
## Applying the patch
The patch will be shipped in releases of wasmvm. You can update more or less as follows:
1. Check the current wasmvm version: `go list -m github.com/CosmWasm/wasmvm` 2. Bump the `github.com/CosmWasm/wasmvm` dependency in your go.mod to one of the patched version depending on which minor version you are on; `go mod tidy`; commit. 3. If you use the static libraries `libwasmvm_muslc.aarch64.a`/`libwasmvm_muslc.x86_64.a`, update them accordingly. 4. Check the updated wasmvm version: `go list -m github.com/CosmWasm/wasmvm` and ensure you see 1.5.8, 2.0.6, 2.1.5 or 2.2.2. 5. Follow your regular practices to deploy chain upgrades.
The patch is consensus breaking and requires a coordinated upgrade.
## Acknowledgement
This issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne.
If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see <https://hackerone.com/cosmos>.
## Timeline
- 2024-11-24: Confio receives a report through the Cosmos bug bounty program maintained by Amulet. - 2024-12-20: Confio security contributors confirm the report. - 2024-01-27: Confio developed the patch internally. - 2025-02-04: Patch gets released.
[^1]: following Amulet's Severity Classification Framework ACMv1.2: https://github.com/interchainio/security/blob/0295254e8645301ccb606d46108a45cede0a73e0/resources/CLASSIFICATION_MATRIX.md
Are you affected?
Enter the version of the package you're using.
Affected packages
2.2.0Fixed in: 2.2.1Upgrade cosmwasm-vm to 2.2.1 or newer (ecosystem crates.io).
2.1.0Fixed in: 2.1.6Upgrade cosmwasm-vm to 2.1.6 or newer (ecosystem crates.io).
2.0.0Fixed in: 2.0.9Upgrade cosmwasm-vm to 2.0.9 or newer (ecosystem crates.io).
0Fixed in: 1.5.10Upgrade cosmwasm-vm to 1.5.10 or newer (ecosystem crates.io).
0.1.0Fixed in: 1.5.8go get github.com/CosmWasm/wasmvm@v1.5.82.2.0Fixed in: 2.2.2go get github.com/CosmWasm/wasmvm/v2@v2.2.22.1.0Fixed in: 2.1.5go get github.com/CosmWasm/wasmvm/v2@v2.1.52.0.0Fixed in: 2.0.6go get github.com/CosmWasm/wasmvm/v2@v2.0.60Fixed in: 0.0.0-20250204093451-1f4db20199b8go get github.com/CosmWasm/wasmvm@v0.0.0-20250204093451-1f4db20199b80Fixed in: 2.0.0-20250204103256-d62c3b826a9dgo get github.com/CosmWasm/wasmvm/v2@v2.0.0-20250204103256-d62c3b826a9d1.5.8-0Fixed in: 1.5.8-0.20250204093451-1f4db20199b8go get github.com/CosmWasm/wasmvm@v1.5.8-0.20250204093451-1f4db20199b82.0.6-0Fixed in: 2.0.6-0.20250204103256-d62c3b826a9dgo get github.com/CosmWasm/wasmvm/v2@v2.0.6-0.20250204103256-d62c3b826a9dReferences
- https://github.com/CosmWasm/wasmvm/security/advisories/GHSA-mx2j-7cmv-353c[WEB]
- https://github.com/CosmWasm/cosmwasm/commit/2b7f2faa57a1efc8207455c37f87f1eee6035a27[WEB]
- https://github.com/CosmWasm/cosmwasm/commit/a5d62f65b5eb947ebe40e2085b1c48a9d0a244d0[WEB]
- https://github.com/CosmWasm/cosmwasm/commit/d6143b0aff16a39bbea4be37597d8e9d9b213d3b[WEB]
- https://github.com/CosmWasm/cosmwasm/commit/f0c04c03cbe2557634c1bbcdc2ce203fe7caca58[WEB]
- https://github.com/CosmWasm/advisories/blob/main/CWAs/CWA-2025-002.md[WEB]
- https://github.com/CosmWasm/wasmvm[PACKAGE]
- https://pkg.go.dev/vuln/GO-2025-3449[WEB]