{ "schema_version": "1.4.0", "id": "GHSA-45p7-c959-rgcm", "modified": "2021-08-02T21:57:02Z", "published": "2021-08-25T21:01:18Z", "aliases": [], "summary": "Process crashes when the cell used as DepGroup is not alive", "details": "### Impact\n\nIt's easy to create a malign transaction which uses the dead cell as the DepGroup in the DepCells. The transaction can crash all the receiving nodes.", "severity": [], "affected": [ { "package": { "ecosystem": "crates.io", "name": "ckb" }, "ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "0" }, { "fixed": "0.40.0" } ] } ] } ], "references": [ { "type": "WEB", "url": "https://github.com/nervosnetwork/ckb/security/advisories/GHSA-45p7-c959-rgcm" }, { "type": "WEB", "url": "https://rustsec.org/advisories/RUSTSEC-2021-0109.html" } ], "database_specific": { "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2021-08-02T21:57:02Z", "nvd_published_at": null } }