Impact
Zebra before 6.1.0 contains an incorrect calculation in its block template selector that omits header and transaction-count size from the block budget. This flaw allows an attacker to create transactions that, when added to a miner's mempool, cause the block size calculation to exceed the network limit, leading to rejected blocks and wasted computational effort. The weakness is a numeric overflow miscalculation (CWE-131).
Affected Systems
The vulnerability affects Zcash Foundation's Zebra nodes with any version prior to 6.1.0. These nodes are used by mining operators and full-node validators in the Zcash network.
Risk and Exploitability
The CVSS score of 6.3 indicates medium severity. EPSS data is not available, and the flaw is not listed in CISA's KEV catalog, suggesting a lower current exploitation probability. The description indicates that an attacker must be able to place transactions into the miner's mempool, although the exact method of access is not specified in the advisory. Successful exploitation causes block rejection and wasted proof-of-work, potentially reducing a miner's revenue.
OpenCVE Enrichment