Description

gnark is a fast zk-SNARK library that offers a high-level API to design circuits. In gnark 0.11.0 and earlier, deserialization of Groth16 verification keys allocate excessive memory, consuming a lot of resources and triggering a crash with the error fatal error: runtime: out of memory.

INFO

Published Date :

2024-10-31T15:59:30.063Z

Last Modified :

2024-10-31T16:53:21.298Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2024-50354 vulnerability.

Vendors Products
Consensys
  • Gnark

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact