Security Bug - BTreeMap memory leak when deallocating nodes with overflows

Dear all,

We recently discovered a memory leak in the BTreeMap implementation of @dfinity/stable-structures, which could lead to consuming an excessive amount of memory. This is a moderate severity security issue and we recommend updating to version 0.6.4. Please see the GitHub Security Advisory for more details.

We encourage the ICP community to report any new issues or bugs found responsibly. Please refer to the Bug Bounty program for more information.

Please reach out to us in this thread or privately if you have any questions.

6 Likes