move-language / move

Apache License 2.0
2.25k stars 684 forks source link

[Bug] A patch for a DoS vulnerability needs to be applied #1059

Closed poetyellow closed 1 year ago

poetyellow commented 1 year ago

There is a critical Move VM vulnerability that has been fixed by Sui move and Aptos move, but this project has not fix that vulnerability.

In addition to Sui and Aptos, some blockchains are also using the Move virtual machine.

Sui move patch link https://github.com/MystenLabs/sui/commit/8b681515c0cf435df2a54198a28ab4ef574d202b

Aptos move patch link https://github.com/aptos-labs/aptos-core/commit/47a0391c612407fe0b1051ef658a29e35d986963

credit : poetyellow

tzakian commented 1 year ago

Thanks for the report @poetyellow! Patch has been landed so closing this out.