Intel

AIKIDO-2024-10533

github.com/cosmwasm/wasmvm is vulnerable to Incorrect Calculation

Incorrect Calculation Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Dec 13, 2024

55

Medium Risk

This Affects:

gogithub.com/cosmwasm/wasmvm
0.12.0 - 1.5.4
Fixed in 1.5.5
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to incorrect calculation due to flaws in the metering logic. These flaws allow attackers to manipulate the execution of smart contracts by exploiting the inaccurate resource metering mechanism. As a result, the package fails to properly account for resource consumption, enabling attackers to bypass limits or other security issues within the smart contract ecosystem.

Who does this affect?

You are affected if you are using a vulnerable version of the package.

Background info

github.com/cosmwasm/wasmvm is vulnerable to Incorrect Calculation in versions 0.12.0 - 1.5.4.

How to fix this

Upgrade the github.com/cosmwasm/wasmvm library to the patch version.