Intel

AIKIDO-2024-10477

cosmossdk.io/math is vulnerable to Integer Overflow or Wraparound

Integer Overflow or WraparoundGHSA-7225-m954-23v7 Published Nov 25, 2024

87

High Risk

This Affects:

gocosmossdk.io/math
1.0.0 - 1.3.0
Fixed in 1.4.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to integer overflow or wraparound caused by inconsistent bit-length validation between sdk.Int and sdk.Dec. This misalignment can lead to unexpected behavior and potential security risks.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges

Background info

cosmossdk.io/math is vulnerable to Integer Overflow or Wraparound in versions 1.0.0 - 1.3.0.

How to fix this

Upgrade the cosmossdk.io/math library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform