Zebra Vulnerable to Allocation Amplification in Inbound Network Deserializers
Zebra Vulnerable to Allocation Amplification in Inbound Network Deserializers. Several inbound deserialization paths in Zebra allocated buffers sized against generic transport or block-size ceilings before the tighter protocol or consensus limits were enforced.
Vuln-watch · relayed from the GitHub Advisory Database; see Source & attribution below
Summary
Several inbound deserialization paths in Zebra allocated buffers sized against generic transport or block-size ceilings before the tighter protocol or consensus limits were enforced.
Affected
- zebra-network (rust) <= 5.0.2 — fixed in 6.0.0
- zebrad (rust) < 4.4.0 — fixed in 4.4.0
- zebra-chain (rust) <= 6.0.3 — fixed in 7.0.0
Severity
Medium, as rated by the upstream advisory.
Recommended actions
- Upgrade zebra-network to 6.0.0 or later
- Upgrade zebrad to 4.4.0 or later
- Upgrade zebra-chain to 7.0.0 or later
Source & attribution
This 0xCERT advisory summarises GHSA-438q-jx8f-cccv / CVE-2026-44500 from the GitHub Advisory Database, credited upstream to Zk-nd3r: https://github.com/advisories/GHSA-438q-jx8f-cccv. Details may change; refer to the original source for the authoritative record.
References
OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.
Published 2026-05-07 · last updated 2026-10-08
curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0192/signed.txt | gpg --verify