From 7af18c4336d1542fb40fd71481751fb2840439d2 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 14 Feb 2025 17:27:34 +0000 Subject: [PATCH] Publish GHSA-5v93-9mqw-p9mh --- .../GHSA-5v93-9mqw-p9mh.json | 63 +++++++++++++++++++ 1 file changed, 63 insertions(+) create mode 100644 advisories/github-reviewed/2025/02/GHSA-5v93-9mqw-p9mh/GHSA-5v93-9mqw-p9mh.json diff --git a/advisories/github-reviewed/2025/02/GHSA-5v93-9mqw-p9mh/GHSA-5v93-9mqw-p9mh.json b/advisories/github-reviewed/2025/02/GHSA-5v93-9mqw-p9mh/GHSA-5v93-9mqw-p9mh.json new file mode 100644 index 00000000000..49eed436286 --- /dev/null +++ b/advisories/github-reviewed/2025/02/GHSA-5v93-9mqw-p9mh/GHSA-5v93-9mqw-p9mh.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5v93-9mqw-p9mh", + "modified": "2025-02-14T17:26:08Z", + "published": "2025-02-14T17:26:08Z", + "aliases": [], + "summary": "Uncaught Panic in ORML Rewards Pallet", + "details": "## Summary\nA vulnerability in the `add_share` function of the **Rewards** pallet (part of the ORML repository) can lead to an uncaught Rust panic when handling user-provided input exceeding the `u128` range.\n\n## Affected Components\n- **ORML Rewards** pallet (`rewards/src/lib.rs`)\n- Any Substrate-based chain using ORML Rewards with `add_share` accepting unvalidated large `u128` inputs\n\n## Technical Details\n- `add_share` performs arithmetic on user-supplied values (`add_amount`) of type `T::Share` (mapped to `u128` in Acala).\n- If `add_amount` is large enough (e.g., `i128::MAX`), the intermediate result may overflow and panic on the cast to `u128`.\n- Validation occurs only after arithmetic, enabling a crafted input to trigger an overflow.\n\n## Impact\nA malicious user submitting a specially crafted extrinsic can cause a panic in the runtime:\n- **Denial of Service** by crashing the node process.\n- **Potential for invalid blocks** produced by validators.\n\n## Likelihood\nThis issue is exploitable in production if there exists at least one rewards pool where reward tokens exceed twice the collateral tokens, allowing sufficiently large multiplication to exceed `u128` bounds.\n\n## Remediation\n- This issue is fixed in https://github.com/open-web3-stack/open-runtime-module-library/pull/1016\n\n## Backport\n\nThe patch have been backported to following release branches:\n- polkadot-stable2407\n- polkadot-stable2409\n\nA 1.0.1 patch release is made with this fix.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "crates.io", + "name": "orml-rewards" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.2.1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/open-web3-stack/open-runtime-module-library/security/advisories/GHSA-5v93-9mqw-p9mh" + }, + { + "type": "WEB", + "url": "https://github.com/open-web3-stack/open-runtime-module-library/pull/1016" + }, + { + "type": "WEB", + "url": "https://github.com/open-web3-stack/open-runtime-module-library/commit/6720fcd92f44e5f204741b04fdef3b67b0fcf6bc" + }, + { + "type": "PACKAGE", + "url": "https://github.com/open-web3-stack/open-runtime-module-library" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-248" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2025-02-14T17:26:08Z", + "nvd_published_at": null + } +} \ No newline at end of file