An issue was discovered in the ckb crate before 0.40.0 for Rust. Attackers can cause a denial of service (Nervos CKB blockchain node crash) via a dead call that is used as a DepGroup.
References:- https://nvd.nist.gov/vuln/detail/CVE-2021-45700
- https://raw.githubusercontent.com/rustsec/advisory-db/main/crates/ckb/RUSTSEC-2021-0109.md
- https://rustsec.org/advisories/RUSTSEC-2021-0109.html
- https://github.com/nervosnetwork/ckb/security/advisories/GHSA-45p7-c959-rgcm
- https://github.com/advisories/GHSA-cw98-cx2m-9qqg