Impact
VestingContract::can_change_balance returns AccountError::InsufficientFunds when new_balance < min_cap, but it constructs the error using balance: self.balance - min_cap. Coin::sub panics on underflow, so if an attacker can reach a state where min_cap > balance, the node crashes while trying to return an error.
The min_cap > balance precondition is attacker-reachable because the vesting contract creation data (32-byte format) allows encoding total_amount without validating total_amount <= transaction.value (the real contract balance). After creating such a vesting contract, the attacker can broadcast an outgoing transaction to trigger the panic during mempool admission and block processing.
Patches
The patch for this vulnerability is formally released as part of v1.3.0.
Workarounds
No known workarounds.
References
See PR.
Impact
VestingContract::can_change_balancereturnsAccountError::InsufficientFundswhennew_balance < min_cap, but it constructs the error usingbalance: self.balance - min_cap.Coin::subpanics on underflow, so if an attacker can reach a state wheremin_cap > balance, the node crashes while trying to return an error.The
min_cap > balanceprecondition is attacker-reachable because the vesting contract creation data (32-byte format) allows encodingtotal_amountwithout validatingtotal_amount <= transaction.value(the real contract balance). After creating such a vesting contract, the attacker can broadcast an outgoing transaction to trigger the panic during mempool admission and block processing.Patches
The patch for this vulnerability is formally released as part of v1.3.0.
Workarounds
No known workarounds.
References
See PR.