CVE-2026-82407
BilinmiyorTeknik Veri (Otomatik)
- CVSS Skoru
- —
- EPSS
- —
- CWE
- CWE-20
- KEV Durumu
- Hayır
Klever-Go, Klever blockchain protokolünün Go dilinde yazılmış uygulamasıdır. 1.7.20 sürümünden önce, core/kapp/validators/validators.go içindeki Register ve runtime validator güncelleme yolu, eğri, prime-sipariş alt grubu veya sıfır olmayan doğrulama olmadan gönderilen bir BLSPublicKey'i kabul eder. Bozuk bir anahtara sahip bir validator seçilme hakkını kazanır ve bir konsensüs grubuna seçilirse, MultiSigner.Reset ve ilgili imza doğrulama oluşturma yolu grup anahtarını seri hale getiremez ve slotu iptal edemez. Bu, tekrarlanan kaçırılan tur ve verimlilik azalmasına neden olur ve konsensüs grubu eşit olan uygun validator setine sahip bir ağ tamamen durabilir. Genesis doğrulaması etkilenmez çünkü bu yol zaten CheckPublicKeyValid işlemini gerçekleştirir. Bu sorun 1.7.20 sürümünde giderilmiştir.
Orijinal açıklama (İngilizce)
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, core/kapp/validators/validators.go Register and the runtime validator update path accept a submitted BLSPublicKey without curve, prime-order subgroup, or nonzero validation. When a validator with a malformed key becomes eligible and is selected into a consensus group, MultiSigner.Reset and the corresponding signature verification creation path cannot deserialize the group key and cancel the slot. This causes repeated missed rounds and throughput degradation, and a network whose consensus group equals the eligible validator set can halt completely. Genesis validation is not affected because that path already performs CheckPublicKeyValid. This issue is fixed in version 1.7.20.
Referanslar
- https://github.com/klever-io/klever-go/commit/11606a90ccc289f93d0175994733229b332d9cff
- https://github.com/klever-io/klever-go/commit/642da967893884d635986fed3c43bdc679cbfe8f
- https://github.com/klever-io/klever-go/releases/tag/v1.7.20
- https://github.com/klever-io/klever-go/security/advisories/GHSA-9wh6-9hq7-9688
- https://github.com/klever-io/klever-go/security/advisories/GHSA-9wh6-9hq7-9688
Bu CVE için henüz editoryal inceleme yapılmadı. Sadece otomatik teknik veri gösteriliyor.
