Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

RUSTSEC-2022-0084: libp2p Lack of resource management DoS #220

Open
standardtech-bot opened this issue Feb 3, 2023 · 0 comments
Open

RUSTSEC-2022-0084: libp2p Lack of resource management DoS #220

standardtech-bot opened this issue Feb 3, 2023 · 0 comments

Comments

@standardtech-bot
Copy link

libp2p Lack of resource management DoS

Details
Package libp2p
Version 0.40.0
URL GHSA-jvgw-gccv-q5p8
Date 2022-07-12
Patched versions >=0.45.1

libp2p allows a potential attacker to cause victim p2p node to run out of memory

The out of memory failure can cause crashes where libp2p is intended to be used
within large scale networks leading to potential Denial of Service (DoS) vector

Users should upgrade or reference the DoS mitigation strategies.

See advisory page for additional details.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant