You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We originally decided not to make any changes here for these reasons. However, we subsequently found an easy fix which are dependent on the ECC team merging. EDIT: It seems like the ECC team are going to implement this in another way.
Optional Tasks
Other miscellaneous remarks that are not considered security vulnerabilities. Fixing these could increase code quality.
Motivation
We want to ensure that we track and act upon findings from the audit.
Scope
zebra
zebra-chain
: Inconsistent error management inAdd
andSub
forHeight
#6279zebra-chain
: Unbounded Rejection Sampling with Possibility of Panics #6338zebra-chain
: Check that header block version field is valid when serializing blocks #497zebra-network
: Buffer length validation after memory allocation #6280zebra-network
: Power-of-Two-Choices Load Balancing May Deprioritize Honest Peers #6343wont-fix
see issue for analysis and decisionzebra-network
: Uncaught Nonce Reuse and Fragile Nonce Cache Eviction #6339zebra-network
: Off-by-One Error inzebra-network
Retry Parameter #6393zebra-consensus
: Off-by-One Errors and Inconsistent Usage ofPARAMETER_DOWNLOAD_MAX_RETRIES
#6340zebra-network
: Fragile State Transition During Address Book Update #6672ed25519-zebra
SigningKey
ed25519-zebra#72librustzcash
zcash_proofs
: Theoretical possibility of overflow leading to panic zcash/librustzcash#786 / [NCC-E005955-NQ6]zcash_proofs
: Theoretical possibility of overflow leading to panic (Copy of zcash/librustzcash#786) #6327zebra-consensus
: Redundant Computation in Sapling and Orchard Note Validation #6392Optional Tasks
Other miscellaneous remarks that are not considered security vulnerabilities. Fixing these could increase code quality.
src/batch.rs
ed25519-zebra#74reddsa
andredjubjub
#6341XXX
used as aTODO
Label #6342TODO
#6344fetch_sprout_final_treestates()
#6389zebra-state
#6673Out of Scope
Other tasks
The text was updated successfully, but these errors were encountered: