Описание
Babylon's malformed vote extensions are not rejected
Summary
Adversarial validators can send large vote extensions by using non-existing protobuf tags. This will result in the rejection of the subsequent block proposal. Eventually, all block proposals will be rejected by all validators.
Impact
A small group of adversarial validators can cause a chain halt.
Пакеты
Наименование
github.com/babylonlabs-io/babylon/v4
go
Затронутые версииВерсия исправления
< 4.1.0
4.1.0
7 High
CVSS4
Дефекты
CWE-770
7 High
CVSS4
Дефекты
CWE-770