PT-2024-40182 · Ckb · Ckb
Published
2024-02-02
·
Updated
2024-02-02
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions:
CKB (affected versions not specified)
Description:
The issue is related to the P2P protocols lacking rate limits. Specifically, in the relay protocol, when a node receives a broadcasted
tx hashes, it marks them in memory to avoid duplicated requests. This can be exploited to launch a denial-of-service (DoS) attack by generating random tx hashes. The issue affects all nodes connected to the P2P network.Recommendations:
Apply rate limits on the data sent to the CKB P2P port to mitigate the risk of exploitation.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ckb