CVE-2026-104422
🟡 Monitoruj
Błąd w Zebra pozwala złośliwemu peerowi opóźnić odkrycie najnowszego bloku.
CVSS
7.5
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)
The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's height from its unvalidated coinbase scriptSig and drops blocks that appear too far behind the tip before consensus validation, without penalizing the supplying peer. Because V5 transaction IDs exclude the scriptSig, a malicious peer can repeatedly serve a canonical block whose coinbase claims height 1 while keeping the requested hash, delaying the node's discovery of the newest block.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-10-02 12:17:12 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-02 18:17:01 UTC |