CVE-2025-59942 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

go-f3 is a Golang implementation of Fast Finality for Filecoin (F3). In versions 0.8.6 and below, go-f3 panics when it validates a "poison" messages causing Fil…
High CVSS: 7.5

CVE-2025-59942

go-f3 is a Golang implementation of Fast Finality for Filecoin (F3). In versions 0.8.6 and below, go-f3 panics when it validates a "poison" messages causing Filecoin nodes consuming F3 messages to become vulnerable. A "poison" message can can cause integer overflow in the signer index validation, which can cause the whole node to crash. These malicious messages aren't self-propagating since the bug is in the validator. An attacker needs to directly send the message to all targets. This issue is fixed in version 0.8.7.
Vendor
Filecoin
Product
Go-f3
CWE
CWE-190
Yayın Tarihi
2025-09-29 23:15:32
Güncelleme
2025-10-18 01:15:14
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar