CVE-2026-104427 Zebra 状态写入任务清理不完整漏洞
影响远程未认证攻击者可阻断节点同步约2000个区块
AI 研判
Zebra 6.1.0 之前版本的状态写入任务存在清理不完整问题,攻击者可污染 parent_error_map。远程未认证节点可借此使节点同步停滞。
影响范围
Zebra
Zebra 6.1.0 之前的版本,具体受影响版本范围暂无公开信息。
漏洞详情
该漏洞属于状态清理不完整类问题。攻击者可在规范区块传播前,投递一个与规范区块共享哈希的 coinbase 篡改区块,污染 parent_error_map,导致下一个规范区块被拒绝,节点同步停滞约 2000 个区块。
利用条件与风险
利用无需认证,远程即可触发,可造成节点同步停滞,属于拒绝服务类风险。
修复建议
建议升级至 Zebra 6.1.0 或更高版本;临时缓解措施暂无公开信息。
原始情报
Zebra before 6.1.0 contains an incomplete cleanup vulnerability in the state write task that allows remote unauthenticated peers to stall node synchronization by poisoning parent_error_map. Attackers can deliver a coinbase-malleated block sharing a canonical block’s hash before it propagates, causing the next canonical block to be rejected and stalling the node for roughly 2,000 blocks.