Описание
Motoko's incremental garbage collector is impacted by an uninitialized memory access bug, caused by incorrect use of write barriers in a few locations. This vulnerability could potentially allow unauthorized read or write access to a Canister's memory. However, exploiting this bug requires the Canister to enable the incremental garbage collector or enhanced orthogonal persistence, which are non-default features in Motoko.
Ссылки
- Issue TrackingPatch
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 0.9.0 (включая) до 0.13.4 (исключая)
cpe:2.3:a:dfinity:motoko:*:*:*:*:*:*:*:*
EPSS
Процентиль: 19%
0.00058
Низкий
5.6 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-908
EPSS
Процентиль: 19%
0.00058
Низкий
5.6 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-908