Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-7884— Memory leak when calling a canister method via `ic_cdk::call`

Quick assessment

Affected
Internet Computer ic-cdk
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Rust Canister Development Kit是DFINITY开源的一个用于 Internet 计算机的 Rust 开发工具包。 Rust Canister Development Kit存在安全漏洞,该漏洞源于在解析 Future 之前并非所有引用都被删除,从而导致内存泄漏。

CVSS 7.5 · High EPSS 0.69% · P51
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-7884

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Memory leak when calling a canister method via `ic_cdk::call`
Source: CVE Program / CVE List V5
Vulnerability Description
When a canister method is called via ic_cdk::call* , a new Future CallFuture is created and can be awaited by the caller to get the execution result. Internally, the state of the Future is tracked and stored in a struct called CallFutureState. A bug in the polling implementation of the CallFuture allows multiple references to be held for this internal state and not all references were dropped before the Future is resolved. Since we have unaccounted references held, a copy of the internal state ended up being persisted in the canister's heap and thus causing a memory leak. Impact Canisters built in Rust with ic_cdk and ic_cdk_timers are affected. If these canisters call a canister method, use timers or heartbeat, they will likely leak a small amount of memory on every such operation. In the worst case, this could lead to heap memory exhaustion triggered by an attacker. Motoko based canisters are not affected by the bug. PatchesThe patch has been backported to all minor versions between >= 0.8.0, <= 0.15.0. The patched versions available are 0.8.2, 0.9.3, 0.10.1, 0.11.6, 0.12.2, 0.13.5, 0.14.1, 0.15.1 and their previous versions have been yanked. WorkaroundsThere are no known workarounds at the moment. Developers are recommended to upgrade their canister as soon as possible to the latest available patched version of ic_cdk to avoid running out of Wasm heap memory. Upgrading the canisters (without updating `ic_cdk`) also frees the leaked memory but it's only a temporary solution.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
在移除最后引用时对内存的释放不恰当(内存泄露)
Source: CVE Program / CVE List V5
Vulnerability Title
Rust Canister Development Kit 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Rust Canister Development Kit是DFINITY开源的一个用于 Internet 计算机的 Rust 开发工具包。 Rust Canister Development Kit存在安全漏洞,该漏洞源于在解析 Future 之前并非所有引用都被删除,从而导致内存泄漏。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Internet Computer ic-cdk 0.8.0 ~ 0.8.2 -

II. Public POCs for CVE-2024-7884

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 8141 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2024-7884

请登录查看更多情报信息。

Other References for CVE-2024-7884 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2024-7884

No comments yet


Leave a comment