NRDAX-T0199 - Peer-Record Flood OOM
Memory amplification · P2P and gossip · no bound · active · first seen 2023-01-01
provenance: Reproduced in NullRabbit's attack-reproduction pipeline
mechanism
CVE-2023-40583: unchecked signed peer-record flood (peer-exchange) → go-libp2p peerstore OOM
live exposure
No exposure data. Slashr ↗ has no risk signal mapped to this technique yet — absence of data is not absence of exposure.
instances (1)
| chain | primitive | fidelity | origin | reproducer (bundle) | source |
|---|---|---|---|---|---|
| libp2p | libp2p_signed_peer_record_flood | lab | reverse-engineered-cve | libp2p_signed_peer_record_flood | GHSA-gcq9-qqwx-rgj3 ↗ |
references
related (Memory amplification)
NRDAX-T0023 - Coalesced Packet Buffer Leak active NRDAX-T0025 - Compact Block Size Integer Overflow active NRDAX-T0038 - Count Underflow Header Serving Amplification active NRDAX-T0042 - Crypto Frame Reassembly Buffer Exhaustion active NRDAX-T0046 - Decompression Bomb Resource Exhaustion active NRDAX-T0059 - Duplicate Transport Parameter Memory Leak active NRDAX-T0061 - Duplicate Tx Mempool Index Desync active NRDAX-T0071 - Ethash Verification Memory Exhaustion active
cite
https://nrdax.com/techniques/NRDAX-T0199
plain
NRDAX Registry. Technique NRDAX-T0199.
bibtex
@misc{nrdax_NRDAX_T0199,
title = {Peer-Record Flood OOM (NRDAX-T0199)},
howpublished = {NRDAX Registry},
url = {https://nrdax.com/techniques/NRDAX-T0199},
} json (csl)
{
"id": "nrdax-NRDAX-T0199",
"type": "dataset",
"title": "Peer-Record Flood OOM (NRDAX-T0199)",
"URL": "https://nrdax.com/techniques/NRDAX-T0199",
"publisher": "NRDAX Registry"
} badge
[](https://nrdax.com/techniques/NRDAX-T0199-peer-record-flood-oom)
use from the CLI
Retrieve or cite this technique from a script or the terminal with the NRDAX Python library & CLI.
nrdax get NRDAX-T0199 nrdax cite NRDAX-T0199 --format bibtex