GHSA-2prc-cj5x-4443 This code looks headache-inducing; the consequence of mismatched Rust implementation and protocol specification is a consensus crisis—Zebra 4.5.1 must be upgraded, no discussion.

View Original
MarsBitNews
Zcash Foundation releases Zebra 4.5.1 emergency update, fixing a critical consensus-level security vulnerability
Zcash Foundation releases Zebra 4.5.1 patch, fixing a consensus-level security vulnerability GHSA-2prc-cj5x-4443, involving a sigop counting error related to P2SH, which could lead to consensus forks. This issue stems from discrepancies in sigop counting across different implementations. The fix involves rolling back and adjusting the Rust implementation to align with the protocol. Upgrading to 4.5.1 is the only way to ensure nodes stay on the correct chain and avoid forks.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned