Loading HuntDB...

Remote denial of service in HyperLedger Fabric

High
H
Hyperledger
Submitted None

Team Summary

Official summary from Hyperledger

This issue was caused by [a missing check of nil](https://github.com/hyperledger/fabric/pull/3494). > An orderer to orderer consensus message that contains an empty inner message crashes the node because it attempts to figure out its type and the mere action of determining the type of a nil pointer, causes a panic. Thank you to Haosheng Wang of OPPO ZIWU Security Lab for this disclosure.

Reported by fatal0

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Uncontrolled Resource Consumption