Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-33cr-m232-xqch

Опубликовано: 11 мар. 2025
Источник: github
Github: Прошло ревью
CVSS4: 9.3

Описание

cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement

Description

An issue was discovered in IBC-Go's deserialization of acknowledgements that results in non-deterministic behavior which can halt a chain. Any user that can open an IBC channel can introduce this state to the chain.

This an upstream dependency used in cheqd-node, rather than a custom module.

Impact

Could result in a chain halt.

Patches

Validators, full nodes, and IBC relayers should upgrade to cheqd-node v3.1.7. This upgrade does not require a software upgrade proposal on-chain and is meant to be non state-breaking.

References

See ASA-2025-004: Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt upstream on IBC-Go.

Пакеты

Наименование

github.com/cheqd/cheqd-node

go
Затронутые версииВерсия исправления

< 3.1.7

3.1.7

9.3 Critical

CVSS4

Дефекты

CWE-502

9.3 Critical

CVSS4

Дефекты

CWE-502