{"id":"GO-2023-2119","summary":"Proof forgery due to insufficient randomness in github.com/consensys/gnark","details":"A a third party may derive a valid proof from a valid initial tuple {proof, public_inputs}, corresponding to the same public inputs as the initial proof. This vulnerability is due to randomness being generated using a small part of the scratch memory describing the state, allowing for degrees of freedom in the transcript. Note that the impact is limited to the PlonK verifier smart contract.","aliases":["GHSA-7p92-x423-vwj6"],"modified":"2024-05-20T16:03:47Z","published":"2023-10-24T20:27:47Z","database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2023-2119"},"references":[{"type":"ADVISORY","url":"https://github.com/Consensys/gnark/security/advisories/GHSA-7p92-x423-vwj6"},{"type":"FIX","url":"https://github.com/Consensys/gnark/commit/3421eaa7d544286abf3de8c46282b8d4da6d5da0"}],"affected":[{"package":{"name":"github.com/consensys/gnark","ecosystem":"Go","purl":"pkg:golang/github.com/consensys/gnark"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.9.1"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/consensys/gnark/backend/plonk/bls12-377","symbols":["Prove","Verify"]},{"path":"github.com/consensys/gnark/backend/plonk/bls12-381","symbols":["Prove","Verify"]},{"symbols":["Prove","Verify"],"path":"github.com/consensys/gnark/backend/plonk/bls24-315"},{"path":"github.com/consensys/gnark/backend/plonk/bls24-317","symbols":["Prove","Verify"]},{"path":"github.com/consensys/gnark/backend/plonk/bn254","symbols":["Prove","Verify"]},{"path":"github.com/consensys/gnark/backend/plonk/bw6-633","symbols":["Prove","Verify"]},{"path":"github.com/consensys/gnark/backend/plonk/bw6-761","symbols":["Prove","Verify"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2023-2119.json"}}],"schema_version":"1.7.3"}