Impact
A malicious state‑sync peer can crash a syncing node by sending a crafted TrieChunk proof that contains two TrieProofNode values with identical keys. When TrieProof::verify processes the equal‑length keys, it calls TrieProofNode::child_index, which accepts equal keys as prefixes and attempts to retrieve a key slice at full length, yielding None, which is then unconditionally unwrapped. Because untrusted ResponseChunk data is validated before cryptographic proof verification, the attacker does not need a valid proof. The bug causes a transient panic; the node restarts and resynchronizes after the crash.
Affected Systems
The affected product is Nimiq core-rs-albatross, specifically all releases prior to 1.6.0. Version 1.6.0 and later contain a fix that removes the unchecked unwrap.
Risk and Exploitability
The CVSS score of 3.7 indicates low severity, and the EPSS score is below 1 %. This issue is not listed in the CISA KEV catalog. Exploitation requires the attacker to be selected as the victim’s state‑sync peer during state sync. Once chosen, the attacker can send a malicious proof payload that results in a transient panic. Following the crash, the node automatically restarts and resynchronizes. The attack vector is therefore a network‑based peer‑to‑peer interaction.
OpenCVE Enrichment
Github GHSA