Skip to content

libssz v0.2.2

Choose a tag to compare

@ilitteri ilitteri released this 27 May 18:06
f4d682b

Caution

Security release — upgrade immediately. This fixes a denial-of-service
vulnerability in SSZ decoding. All prior versions (≤ 0.2.1) are affected.
When decoding untrusted SSZ bytes, a crafted input of only a few bytes could
force a multi-gigabyte memory allocation (~10⁶× amplification), causing memory
exhaustion / OOM. If you decode untrusted SSZ (p2p, RPC/API, file input),
upgrade to 0.2.2. There is no workaround other than upgrading.

Security fix

Unbounded pre-allocation in list decoding (#24). Vec<T>, List[T, N]
(SszList), and ProgressiveList decoding read an item count from the input's
first offset and reserved capacity for it before validating that offset against
the buffer length or the list's declared maximum. A crafted input could declare
~10⁹ items in a handful of bytes, forcing an ~8 GB allocation before any check
rejected it. The buffer-length and max-length bounds are now enforced before any
allocation.

  • Affected: any caller of from_ssz_bytes on untrusted input.
  • Fixed in: 0.2.2. Workaround: none — upgrade.
  • Backward compatible: no API or error-contract changes for valid inputs.

Follow-up test/fuzz coverage hardening tracked in #25.

Full changelog: v0.2.1...v0.2.2