Intel

AIKIDO-2024-10477

cosmossdk.io/math is vulnerable to Integer Overflow or Wraparound

Integer Overflow or WraparoundGHSA-7225-m954-23v7 Published Nov 25, 2024

87

High Risk

This Affects:

gocosmossdk.io/math
1.0.0 - 1.3.0
Fixed in 1.4.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to integer overflow or wraparound caused by inconsistent bit-length validation between sdk.Int and sdk.Dec. This misalignment can lead to unexpected behavior and potential security risks.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges

Background info

cosmossdk.io/math is vulnerable to Integer Overflow or Wraparound in versions 1.0.0 - 1.3.0.

How to fix this

Upgrade the cosmossdk.io/math library to the patch version.