Описание
Gas mispricing in cosmwasm-vm
Component: wasmvm Criticality: Medium (ACMv1: I:Moderate; L:Likely) Patched versions: wasmvm 1.5.4, 2.0.3, 2.1.2
Some Wasm operations take significantly more gas than our benchmarks indicated. This can lead to missing the gas target we defined by a factor of ~10x. This means a malicious contract could take 10 times as much time to execute as expected, which can be used to temporarily DoS a chain.
See CWA-2024-004 for more details.
Ссылки
- https://github.com/CosmWasm/wasmvm/security/advisories/GHSA-rg2q-2jh9-447q
- https://github.com/CosmWasm/cosmwasm/commit/5bef1c588933bd60a04bb70099150cf84b69e144
- https://github.com/CosmWasm/cosmwasm/commit/9b4d6d03772b75d500a7d3c972d0d8ba6d085c06
- https://github.com/CosmWasm/cosmwasm/commit/c1313afeb261e17b1c8cf6a1eacee1da0dac42ae
- https://github.com/CosmWasm/advisories/blob/main/CWAs/CWA-2024-004.md
- https://rustsec.org/advisories/RUSTSEC-2024-0361.html
Пакеты
cosmwasm-vm
< 1.5.6
1.5.6
cosmwasm-vm
>= 2.0.0, < 2.0.5
2.0.5
cosmwasm-vm
>= 2.1.0, < 2.1.2
2.1.2
github.com/CosmWasm/wasmvm/v2
>= 2.1.0, < 2.1.2
2.1.2
github.com/CosmWasm/wasmvm/v2
>= 2.0.0, < 2.0.3
2.0.3
github.com/CosmWasm/wasmvm
< 1.5.4
1.5.4
5.3 Medium
CVSS4
4.3 Medium
CVSS3
Дефекты
5.3 Medium
CVSS4
4.3 Medium
CVSS3