-
Notifications
You must be signed in to change notification settings - Fork 107
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Halborn 2023 02 20 #6297
Merged
Merged
Halborn 2023 02 20 #6297
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
dconnolly
added
P-Critical 🚑
C-security
Category: Security issues
A-rust
Area: Updates to Rust code
A-network
Area: Network protocol updates or fixes
labels
Mar 13, 2023
conradoplg
approved these changes
Mar 13, 2023
arya2
approved these changes
Mar 13, 2023
Codecov Report
Additional details and impacted files@@ Coverage Diff @@
## main #6297 +/- ##
==========================================
- Coverage 77.84% 77.80% -0.04%
==========================================
Files 304 304
Lines 39366 39481 +115
==========================================
+ Hits 30643 30719 +76
- Misses 8723 8762 +39 |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
A-network
Area: Network protocol updates or fixes
A-rust
Area: Updates to Rust code
C-security
Category: Security issues
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Motivation
This PR fixes some issues we found when investigating the Halborn disclosures from February 2023, and other related network protocol memory usage issues.
The security researchers looked at the
zebrad
codebase and said their exploit will not work against it as-is.Specifications
Most of these network protocol limits are undocumented, see the code comments for specific links to
zcashd
source code.Complex Code or Requirements
These are network protocol changes, they are compatible with other implementations under normal usage.
There are no consensus-critical or concurrent code changes.
Solution
This PR contains the simplest possible fixes to these issues.
Halborn:
Testing:
Related - similar attack:
Testing:
Less urgent
These fixes are not urgent, but we'll do them at the same time anyway:
Testing:
Doesn't need to be in the initial fix or release:
Review
Reviewed by several people privately already.
Reviewer Checklist
Follow Up Work