56826 sc medium attacker can bloat a victim s stakes array and cause withdrawals emergency flows to run out of gas
Description
Brief/Intro
Vulnerability Details
function _deposit(...) internal override {
super._deposit(...);
// locks freshly minted shares
stakes[to].push(Stake({shares: shares, timestamp: block.timestamp}));
}Why it is exploitable (realistic attacker path)
Impact Details
References
Proof of Concept
Mitigation suggestions (not exhaustive)
Previous57942 sc critical transferred slong shares are permanently unredeemable due to missing stake entry creationNext57610 sc medium venues can steal from customers by replaying payments via belongcheckin paytovenue
Was this helpful?