CNNVD-202509-4319 Information

CNNVD ID

CNNVD-202509-4319

CVE-2025-59942

  • CNNVD Published: 2025-09-29

Description (Chinese)

Go implementation of Fast Finality in Filecoin是Filecoin开源的一个快速确认机制的Golang库。 Go implementation of Fast Finality in Filecoin 0.8.6及之前版本存在输入验证错误漏洞,该漏洞源于验证特制消息时存在整数溢出,可能导致节点崩溃。

Description (English)

Go application of Fast Financiality in Filecoin is a Golang library of the Filecoin open source. Go input authentication of Fast Financiality in Filecoin 0.8.6 and previous versions have input authentication bugs, which result from integer spills at the time of authentication of special messages, which may lead to nodal collapse.

Hazard Level

Medium

Vulnerability Type

输入验证错误

Affected Vendor

Filecoin

Published

2025-09-29

Last Modified

2026-02-24

References

https://github.com/filecoin-project/go-f3/security/advisories/GHSA-g99p-47x7-mq88

Patch

https://github.com/filecoin-project/go-f3/releases

Share on: