Junglewise Threat Intelligence

CVE-2022-29219: ChainSafe Lodestar number overflow in AttesterSlashing

CVE-2022-29219 · Severity: low · CVSS 3.1 · Published 2022-05-24

Vendors: npm.

Executive brief

Lodestar is an Ethereum consensus client used to validate and propose blocks on the Ethereum network. A number representation flaw allows maliciously crafted slashing messages to be mishandled, causing nodes to disagree with the network and fork away from consensus, disrupting network participation and potentially allowing invalid blocks to propagate.

Technical details

The vulnerability is an integer overflow/precision loss issue (CWE-190) in how Lodestar represents uint64 values as native JavaScript numbers. When AttesterSlashing or ProposerSlashing objects with large uint64 values (greater than 2^53) are included on-chain, JavaScript's number type loses precision due to rounding. This causes Lodestar to incorrectly validate slashing messages: valid messages are rejected due to rounding errors, and invalid messages may be accepted and included in proposed blocks. The result is a consensus split where Lodestar nodes diverge from the main network. The vulnerability affects all versions prior to 0.36.0 and requires malicious on-chain data to trigger; no user interaction or authentication is needed. A fix using BigInt for critical values was merged and released in version 0.36.0.

Affected products

  • ChainSafe Lodestar <0.36.0

Timeline

  • 2022-05-24: disclosed
  • 2022-05-24: patched: Version 0.36.0 released

References

Related threats