Impact
Zebra nodes count P2SH redeem script signature operations in legacy mode, overcounting CHECKMULTISIG operations as 20 sigops when preceded by OP_1 through OP_16. This discrepancy allows an attacker to construct a transaction whose actual sigop count is within the block limit but the Zebra node rejects it as exceeding the inflated MAX_BLOCK_SIGOPS, leading to a consensus divergence. Nodes that reject such blocks become out‑of‑sync with the network, potentially causing a chain split and denying service to legitimate users.
Affected Systems
The affected products are ZcashFoundation Zebra zebrad version 4.5.0 and zebra‑script version 7.0.0. Only these versions contain the incorrect P2SH sigops counting logic and thus are susceptible to the described behavior.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity of the flaw. EPSS data is not available, so the current exploitation probability cannot be quantified. The flaw is listed as not in KEV. Attacks can be launched remotely by broadcasting a malicious transaction, so the likely attack vector is network transmission of a specially crafted transaction. Any node running the vulnerable ZcashFoundation Zebra versions can be impacted if it accepts a block that zcashd treats as valid. The risk is that an attacker could repeatedly send such transactions to cause nodes to reject blocks, leading to a persistent network split.
OpenCVE Enrichment