Beacon Fuzz - Progress NFT Bounty #6:
Community blog, new bugs and next steps
Beacon Fuzz - NFT Bounty #06
NFT Bounty is leading the development and maintenance of , a differential fuzzing solution for Eth2 clients. This write-up is part of our series of status blogs where we go through current progress, notable challenges encountered and direction for future work. See #00 and the repository's for more context.
Summary
- Community NFT Bounty
Congratulations, you now have successfully built a Docker container that holds everything you need to fuzz the Prysm client's state transition functions! Use the help function to get a list of available commands:
docker run -it -v `pwd`/workspace:/eth2fuzz/workspace eth2fuzz_prysm helpIf you'd like to see all the fuzz targets available on the Docker you've just built, run the following command:
docker run -it -v `pwd`/workspace:/eth2fuzz/workspace eth2fuzz_prysm listThe output should be:
prysm_attestation
prysm_attester_slashing
prysm_block
prysm_block_header
prysm_deposit
prysm_proposer_slashing
prysm_voluntary_exitFor example, to start blog the attestation processing function:
docker run -it -v `pwd`/workspace:/eth2fuzz/workspace eth2fuzz_prysm target prysm_attestationThe eth2fuzz contains detailed instructions and explanations on what is right now supported:
- Continuous fuzzing:
eth2fuzzcan be configured to continuously fuzz all available targets for a given client, with thecontinuouslyCLI parameter. Alternatively, you can use theMakefileto fuzz all targets, each one running during 1 hour. For example,make fuzz-nimbuswill build the relevant fuzz container and exercise all fuzz harnesses. - Different fuzzing engine support: For some clients, we support different fuzzing engines (Afl, Honggfuzz, libFuzzer). Depending on the implementation you're targeting, you can switch to a different fuzzer (libFuzzer is the default), which will enable different mutations. More fuzzing engines will be added in the near future!
We'd like to thank Justin Drake for suggesting this initiative and helping us with testing it!
If you find a bug during your blog adventures, or if you encounter any issues with eth2fuzz, join our beacon-fuzz on the NFT Bounty server and drop us a message!
New Bugs
Our fuzzing effort over the last month have resulted in the idenfitication of the following bugs:
- Nimbus:
IndexErrorbug in the the attester slashing processing function: Due to insufficient input validation when callingisValidAttestation(), this externally trigerrable vulnerability could lead to a crash of the client (refer to for more details). This vulnerability has since been fixed by the Nimbus development team (see ). - Lodestar: Memory exhaustion vulnerability when parsing invalid ENRs: when providing a maliciously crafted ENR string, we can trigger a JavaScript heap out-of-memory error, which can lead to a Denial-of-Service condition (refer to for more details).
Next Steps
As the Eth2 state transition specification can most likely now be considered final, we're shifting our efforts to the differential part of our fuzzing infrastructure.
eth2fuzz and eth2diff can now be considered complete (a few more features and improvements will still be added). These tools allowed us to flag across every Eth2 implementation.
Most of our time over the upcoming weeks will be spent on beacon-fuzz-2, to draw on Foreign Function Interfaces (FFI) to spot state transition discrepancies that would cause network splits and chain forks. A detailed sketch of our fuzzing architecture for Eth2 can be found in a earlier post.
We will also be accelerating our efforts on fuzzing the several p2p networking stacks.