Skip to content

fix: P2P: block merkle roots not validated before inserting into archive DB - #45

Closed
giaki3003 wants to merge 2 commits into
LayerTwo-Labs:masterfrom
giaki3003:fix/s2-r22-p2p-block-merkle-roots-not-validated-before-inse
Closed

fix: P2P: block merkle roots not validated before inserting into archive DB#45
giaki3003 wants to merge 2 commits into
LayerTwo-Labs:masterfrom
giaki3003:fix/s2-r22-p2p-block-merkle-roots-not-validated-before-inse

Conversation

@giaki3003

Copy link
Copy Markdown
Contributor

Summary

P2P: block merkle roots not validated before inserting into archive DB

The bug

P2P: block merkle roots not validated before inserting into archive DB

Severity: Medium. Full technical write-up (access-controlled): https://giaki3003.tech/#/findings/20260603-2200-thunder-peer-body-poison-archive-and-net-task-halt

Notes

First of a short series of fixes for this repo from a security review; the remaining fixes stack on this branch and will follow as separate PRs. Happy to adjust scope or split further on request.

giaki3003 and others added 2 commits July 4, 2026 19:03
…ive DB

Bug: s2-r22 (primary)
Finding: https://giaki3003.tech/#/findings/20260603-2200-thunder-peer-body-poison-archive-and-net-task-halt
Severity: Medium

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ive DB

Bug: s2-r22 (port)
Finding: https://giaki3003.tech/#/findings/20260603-2200-thunder-peer-body-poison-archive-and-net-task-halt
Severity: Medium

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@giaki3003
giaki3003 force-pushed the fix/s2-r22-p2p-block-merkle-roots-not-validated-before-inse branch from 5732a09 to a30437b Compare July 4, 2026 17:03
@giaki3003

Copy link
Copy Markdown
Contributor Author

Closing as a duplicate — this bug is shared across the Rust L2s, so per the maintainer's plan it's submitted once against Thunder (LayerTwo-Labs/thunder-rust#104) and backported from there.

@giaki3003 giaki3003 closed this Jul 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant