Remote denial of service in HyperLedger Fabric
High
H
Hyperledger
Submitted None
Team Summary
Official summary from Hyperledger
This issue was caused by [a missing check of nil](https://github.com/hyperledger/fabric/pull/3494). > An orderer to orderer consensus message that contains an empty inner message crashes the node because it attempts to figure out its type and the mere action of determining the type of a nil pointer, causes a panic. Thank you to Haosheng Wang of OPPO ZIWU Security Lab for this disclosure.
Actions:
Reported by
fatal0
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Uncontrolled Resource Consumption