GHSA-q73f-w3h7-7wcc

Suggest an improvement
Source
https://github.com/advisories/GHSA-q73f-w3h7-7wcc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-q73f-w3h7-7wcc/GHSA-q73f-w3h7-7wcc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-q73f-w3h7-7wcc
Published
2024-02-03T00:18:13Z
Modified
2024-02-03T00:18:13Z
Summary
Nervos CKB Transaction which calls syscall load_cell_data_hash has nondeterministic result
Details

Impact

Tx-pool verify transaction which inputs' script contains load_cell_data_hash is nondeterministic

Workarounds

Enforce tx-pool ResolvedTrascation inputs' load data is none.

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [],
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2024-02-03T00:18:13Z"
}
References

Affected packages

crates.io / ckb

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.34.2

Database specific

{
    "last_known_affected_version_range": "<= 0.34.1"
}