A bug in wasmvm has been discovered.
This bug
- can potentially crash the node,
- can potentially cause consensus failures.
No code path is known to the author that can cause 1 or 2, but this does not guarantee such paths do not exist. If there exists a way to abuse the bug, it is non-trivial to find.
Both 0.16 and 1.0 are equally affected. Both versions will receive a patch. Some older versions are probably affected as well but will not receive an update.
The patch is potentially consensus breaking. However, no code path is known to the author in which the patch breaks consensus.
The release is scheduled for Wednesday, November 10th at 10am Berlin time. An update is recommended for all users.