PT-2022-23019 · Samurai · Samourai Wallet Stonewallx2
Alicexbt
+1
·
Published
2022-09-06
·
Updated
2022-09-16
·
CVE-2022-35913
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Samourai Wallet Stonewallx2 version 0.99.98e
Description
The issue allows a denial of service via a P2P coinjoin. The attacker and victim must follow each other's paynym. Then, the victim must try to collaborate with the attacker for a Stonewallx2 transaction. Next, the attacker broadcasts a tx, spending the inputs used in Stonewallx2 before the victim can broadcast the collaborative transaction. The attacker does not signal opt in RBF, and uses the lowest fee rate. This would result in the victim being unable to perform Stonewallx2. The attacker could use multiple paynyms.
Recommendations
As a temporary workaround, consider disabling the Stonewallx2 feature until a patch is available. Restrict access to P2P coinjoin transactions to minimize the risk of exploitation. Avoid collaborating with untrusted paynyms for Stonewallx2 transactions.
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Samourai Wallet Stonewallx2