libp2p / libp2p/cpp-libp2p

libp2p nodes vulnerable to OOM attack

Open
#295 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
C++
Stars
492
Forks
130
PR merge metrics
No merged PRs in 30d

Description

Summary

This can occur because when a signed peer record is received, only the signature validity check is performed but the sender signature is not checked. Signed peer records from randomly generated peers can be sent by a malicious actor. A target node will accept the peer record as long as the signature is valid, and then stored in the peer store.

Expected behavior

reject peer on peer ID mismatch

Actual behavior

saved the mismatched peer

Relevant log output

Possible Solution

reject peer on peer ID mismatch

Version

No response

Would you like to work on fixing this bug ?

Yes

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

The issue names no files, tests, or entry points. Start by tracing signed peer record handling through peer ID validation and the peer store; done means a peer record with a mismatched peer ID is rejected rather than saved.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
networking, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.