Skip to content

A node can be made to crash by a suitably crafted network message during the connection handshake phase.

Critical
abizjak published GHSA-jg75-6h5x-2g8h Apr 28, 2022

Package

concordium-node (Concordium)

Affected versions

< 3.0.2

Patched versions

3.0.2, >= 4

Description

Impact

A node can be made to crash by a suitably crafted network message during the noise handshake phase. There is no workaround and an attacker could force the entire network to stop by either connecting to nodes, or accepting connections to nodes and issuing malformed packages during the handshake.

References

This is caused by an array out of bounds issue in the noise explorer. See GHSA-wp5m-gj88-8pvg for details.

Severity

Critical

CVE ID

No known CVE

Weaknesses

No CWEs