Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-mcmr-49x3-4jqm: ckb type_id script resume may randomly fail

Impact

https://github.com/nervosnetwork/ckb/blob/v0.101.2/script/src/verify.rs#L871-L879 TypeIdSystemScript resume handle is not correct when max_cycles is not enough, ScriptError::ExceededMaximumCycles will be raised directly ranther than suspend as expect, and also because script_group execution order is random, so this will happen randomly.

ghsa
#git

ckb type_id script resume may randomly fail

High severity GitHub Reviewed Published Nov 2, 2022 in nervosnetwork/ckb • Updated Nov 2, 2022

ghsa: Latest News

GHSA-7p9f-6x8j-gxxp: CRI-O: Maliciously structured checkpoint file can gain arbitrary node access