enforce the collection capacity before adding a data-path element
fixed in public source; rollout not reverified
details
Finding IDs
F-LEDGER-ETH-GCS-COLLECTION-OOBWRITE-001
Status
fixed in public source; rollout not reverified
Disclosure date
Note
the collection capacity check changes from > MAX to >= MAX before the write. The public commit is dated March 6; this is not a claimed release date. Mapping is based on the reported callsite, not a vendor severity assessment or public finding-ID attribution.
F-LEDGER-ETH-GCS-COLLECTION-OOBWRITE-001: Memory safety. Generic clear-signing collection parsing writes outside its buffer. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Security area (1seal assessment): Memory safety. The data-path collection must reject an element before an out-of-bounds array write. Reviewed 23 Sep 2026.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.