-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
DOS function inflate()
if inflationIntervalsElapsed
is too large
#652
Labels
bug
Something isn't working
downgraded by judge
Judge downgraded the risk level of this issue
duplicate-653
QA (Quality Assurance)
Assets are not at risk. State handling, function incorrect as to spec, issues with clarity, syntax
sponsor duplicate
Sponsor deemed duplicate
Comments
C4-Staff
added a commit
that referenced
this issue
Jan 6, 2023
Best because code snippet, but could have been improved via gas math or a test |
GalloDaSballo marked the issue as primary issue |
duplicate of #132 |
GalloDaSballo marked the issue as partial-25 |
dupe of #139 |
GalloDaSballo marked the issue as duplicate of #139 |
GalloDaSballo marked the issue as not a duplicate |
Duplicate of #653 |
L |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
bug
Something isn't working
downgraded by judge
Judge downgraded the risk level of this issue
duplicate-653
QA (Quality Assurance)
Assets are not at risk. State handling, function incorrect as to spec, issues with clarity, syntax
sponsor duplicate
Sponsor deemed duplicate
Lines of code
https://github.com/code-423n4/2022-12-gogopool/blob/aec9928d8bdce8a5a4efe45f54c39d4fc7313731/contracts/contract/RewardsPool.sol#L74
Vulnerability details
Impact
Whenever working with for loop on EVM, gas consumption should be taken care. If the loop is unbounded, it can consume gas even more than block gas limit and effectively DOS the functionality.
It is noticed that
RewardsPool.getInflationAmt()
calculatenewTotalSupply
by looping throughinflationIntervalsElapsed
. If it is too long since last update,inflationIntervalsElapsed
can become too large and cause out of gas. Also, functiongetInflationAmt()
is used ininflate()
soinflate()
will be DOS too.Proof of Concept
Function
getInflationAmt()
used a unbounded loopTools Used
Manual Review
Recommended Mitigation Steps
Consider adding a constant max value for
inflationIntervalsElapsed
so it cannot get too large and cause DOS.The text was updated successfully, but these errors were encountered: