GHSA-mcmr-49x3-4jqm

Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-mcmr-49x3-4jqm/GHSA-mcmr-49x3-4jqm.json
Published
2022-11-02T18:15:07Z
Modified
2022-11-02T18:15:07Z
Details

Impact

https://github.com/nervosnetwork/ckb/blob/v0.101.2/script/src/verify.rs#L871-L879 TypeIdSystemScript resume handle is not correct when maxcycles is not enough, ScriptError::ExceededMaximumCycles will be raised directly ranther than suspend as expect, and also because scriptgroup execution order is random, so this will happen randomly.

References

Affected packages

crates.io / ckb

ckb

Affected ranges

Type
SEMVER
Events
Introduced
0.100.0
Fixed
0.102.0

Affected versions