PANews reported on May 30 that the Zcash Foundation released an update to the node client Zebra, version 4.5.0. This version includes several security fixes, including a critical consensus vulnerability and several high-risk denial-of-service (DoS) issues. All node operators are strongly advised to upgrade immediately.
It is understood that the core fixes include a sigop counting error caused by P2SH script parsing (which may lead to a fork with zcashd consensus), a defect in NU5 block verification cache logic, a risk of crash due to transparent address balance overflow, and multiple crashes and resource exhaustion vulnerabilities in RPC interfaces and memory pool processing. In addition, some vulnerabilities can be exploited by malicious nodes to cause nodes to freeze, restart loops, or even permanently stop running.




