Improper validation of integrity check value in Fabric - CVE-2023-46132
Published: November 14, 2023 / Updated: April 23, 2026
Fabric
hyperledger
Description
The vulnerability allows a remote user to cause a state fork and alter ledger state.
The vulnerability exists due to improper integrity check in block transaction hashing when processing cross-linked blocks. A remote user can craft a cross-linked block to cause a state fork and alter ledger state.
In Fabric v1 and v2, exploitation can occur when a peer replicates a block from a malicious peer. In Fabric v3 preview, a malicious orderer can also cause the issue.