GHSA-j494-7x2v-vvvp

    Dashboard / Vulnerabilities / GHSA-j494-7x2v-vvvp

    GHSA-j494-7x2v-vvvp

    Published: 13 Jul 2023Last Modified: 20 Aug 2024

    Summary: mx-chain-go's relayed transactions always increment nonce

    Details: ### Impact When executing a relayed transaction, if the inner transaction failed, it would have increased the inner transaction's sender account nonce. This could have contributed to a limited DoS attack on a targeted account. The fix is a breaking change so a new flag `RelayedNonceFixEnableEpoch` was needed. This was a strict processing issue while validating blocks on a chain. ### Patches v1.4.17 and later versions contain the fix for this issue ### Workarounds there were no workarounds for this issue. The affected account could only wait for the DoS attack to finish as the attack was not free or to attempt to send transactions in a very fast manner so as to compete on the same nonce with the attacker. ### References For the future understanding of this issue, on v1.4.17 and onwards versions, we have this integration test that addresses the issue and tests the fix. https://github.com/multiversx/mx-chain-go/blob/babdb144f1316ab6176bf3dbd7d4621120414d43/integrationTests/vm/txsFee/relayedMoveBalance_test.go#LL165C14-L165C14

    Affected packages

    Package

    Name: github.com/multiversx/mx-chain-go

    Purl: pkg:golang/github.com/multiversx/mx-chain-go

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.4.17

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-j494-7x2v-vvvp | CVE-DB