漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Klever-Go: Unauthenticated nil-pointer DoS in P2P transaction validation can halt the chain
Vulnerability Description
Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-pointer panic triggered by a protobuf Transaction whose embedded RawData sub-message is omitted. This omission causes RawData to decode to nil. Every transaction gossiped on the Klever-Go P2P network is decoded and validated synchronously inside the libp2p pubsub topic-validator callback, where txVersionChecker.CheckTxVersion dereferences tx.RawData.Version with no nil check. Because the libp2p pubsub callback, the underlying go-libp2p-pubsub validation worker, and Klever's own network/p2p layer install no recover(), the panic propagates and crashes the entire node process. The attacker payload is a 3-byte protobuf message; no validator key, stake, funds, or on-chain account is required, and delivery aimed at enough of the BLS validator set can halt block production, resulting in a chain halt. This issue has been fixed in version 1.7.18.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
空指针解引用
Vulnerability Title
Klever 异常处理不当漏洞
Vulnerability Description
Klever是Klever组织的一个高性能区块链网络,专为去中心化应用、资产管理和智能合约执行而设计。 Klever 1.7.14版本至1.7.17版本存在异常处理不当漏洞,该漏洞源于protobuf Transaction的RawData子消息缺失导致空指针解引用,可能导致攻击者通过发送特制消息使节点进程崩溃,停止区块生产并导致链停止。
CVSS Information
N/A
Vulnerability Type
N/A