mirror of
https://github.com/OMGeeky/advisory-db.git
synced 2026-02-13 21:18:11 +01:00
494 B
494 B
[advisory]
id = "RUSTSEC-2021-0109"
package = "ckb"
date = "2021-07-25"
url = "https://github.com/nervosnetwork/ckb/security/advisories/GHSA-45p7-c959-rgcm"
aliases = ["CVE-2021-45700", "GHSA-45p7-c959-rgcm", "GHSA-cw98-cx2m-9qqg"]
[versions]
patched = [">= 0.40.0"]
Process crashes when the cell used as DepGroup is not alive
It's easy to create a malign transaction which uses the dead cell as the DepGroup in the DepCells. The transaction can crash all the receiving nodes.