Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Report Phase 2 for Rooch Project #3113

Open
steelgeek091 opened this issue Dec 27, 2024 · 0 comments
Open

Security Report Phase 2 for Rooch Project #3113

steelgeek091 opened this issue Dec 27, 2024 · 0 comments

Comments

@steelgeek091
Copy link
Collaborator

steelgeek091 commented Dec 27, 2024

Up to now, in the second phase of Rooch Bug Bounty, we have received 2 high-level security reports and 2 medium-level security reports. We thank all security report submitters. We take code security very seriously and have made these 4 security reports public, encouraging everyone to actively participate in the security audit of Rooch codebase.

The following shows the 4 severity levels in Rooch security report ratings:

Critical-Risk Vulnerability:
No reports available


High-Risk Vulnerability:

  1. 同时查询多个相同的 Object 导致内存快速进程耗尽 @m4sterchain
  2. 字节码中对象过多导致进程内存耗尽 @m4sterchain

Medium-Risk Vulnerability:

  1. 错误的值更新方式导致 grow_information.move 中不一致的状态 @nathanogaga118
  2. 传递过大的 maxInactiveInterval 导致整数运算溢出 @baicaiyihao

Low-Risk Vulnerability:
No reports available

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: No status
Development

No branches or pull requests

1 participant