Skip to content

fix(security): bump evm to GHSA Aug-2026 patched commit (mainnet/v36) - #4637

Merged
skosito merged 1 commit into
release/v36from
sec/mainnet-v36-vuln-patch
Sep 3, 2026
Merged

skosito merged 1 commit into
release/v36from
sec/mainnet-v36-vuln-patch

Conversation

@skosito

@skosito skosito commented Sep 3, 2026 •

Copy link
Copy Markdown
Member

Mainnet (node release/v36) node-side of the fix. One line: bumps the cosmos/evm replace to the patched commit.

github.com/cosmos/evm => github.com/zeta-chain/evm v0.0.0-20260903155132-51190f042d34

51190f04 is the current tip of zeta-chain/evm's release/v35 — the fork line mainnet's v36 pins — after zeta-chain/evm#36 merged. It carries:

  • SubBalance underflow guard + ParseAmount extended-denom handling

  • AddBalance overflow guard

  • StateDB.Commit() atomicity (cache-context staging)

  • the module-account guard, gated on the chain's blocked-receive policy

  • snapshot locked balance on the statedb account

  • x/ibc/callbacks onPacketTimeout: cachedCtx, not the live ctx

  • Logic-only: no module-set change, no store migration, no upgrade handler → ships as an ordinary v36.x patch (handlers key on major version).

  • Vesting-module drop is intentionally NOT here — it changes the module version map and needs a coordinated upgrade; separate, non-urgent.

Note on the pin

Pinned to the merged release/v35 tip rather than to a commit on the PR branch. #36 was squash-merged, so the pre-merge commits are unreachable from any branch and a pseudo-version naming one of them would break as soon as the PR branch is deleted.

The v0.0.0- prefix matches the existing convention in this replace block. Note that go mod tidy would canonicalise it to v1.0.0-rc2.0.20260903155132-51190f042d34 (the repo has a reachable v1.0.0-rc2 tag); both resolve to the same commit but hash differently in go.sum, so don't mix the two forms.

Verification

go build ./cmd/zetacored is green and produces a working binary. No GOPRIVATE needed — the evm dependency is public.


Note

High Risk
Changes consensus-critical EVM/state and IBC callback behavior via a dependency swap; incorrect pinning or missed rollout could leave nodes on vulnerable logic despite no local code diff.

Overview
Security patch for mainnet release/v36: bumps only the replace pin for github.com/cosmos/evm to github.com/zeta-chain/evm at commit 51190f042d34 (tip of the fork’s release/v35 line after zeta-chain/evm#36), with matching go.sum entries.

No node application code, module set, store migrations, or upgrade handlers change—this ships as a normal v36.x patch binary that pulls in upstream EVM fixes (balance underflow/overflow guards, StateDB.Commit atomicity, module-account receive policy, snapshot locked balance, IBC callback timeout context isolation, and related hardening).

The pin uses the existing v0.0.0-… pseudo-version convention rather than go mod tidy’s v1.0.0-rc2.0.… form so go.sum stays consistent with prior pins.

Reviewed by Cursor Bugbot for commit 5de9c71. Configure here.

Greptile Summary

The PR advances the github.com/cosmos/evm replacement to the patched ZetaChain EVM commit for the mainnet v36 release line.

  • Updates the replacement pseudo-version in go.mod.
  • Adds the corresponding module and go.mod checksums to go.sum.
  • Leaves the dependency manifest and transitive version graph otherwise unchanged.

Confidence Score: 5/5

The PR appears safe to merge, with the dependency pin and checksums aligned and no changed-code defect identified.

The replacement advances only the EVM source revision, preserves the module dependency graph, and includes matching checksums; the stated node build verification further confirms that the pin resolves and compiles.

Important Files Changed

Filename Overview
go.mod Updates the Cosmos EVM replacement to the intended patched fork commit without changing other dependency versions.
go.sum Adds checksums corresponding to the new EVM pseudo-version; its module-manifest checksum matches the previous pin.

Reviews (1): Last reviewed commit: "fix(security): bump cosmos/evm to GHSA A..." | Re-trigger Greptile

…et/v36)

Points the evm dependency at the patched release/v35 tip
(github.com/zeta-chain/evm @ 51190f04, zeta-chain/evm#36) carrying the
statedb underflow/overflow/atomicity guards, the module-account guard
gated on the chain's blocked-receive policy, and the x/ibc/callbacks
packet-timeout context fix.

Logic-only; no module-set/store change, no upgrade handler.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@skosito
skosito requested a review from a team as a code owner September 3, 2026 15:57
@skosito skosito added the no-changelog Skip changelog CI check label Sep 3, 2026
@skosito
skosito enabled auto-merge (squash) September 3, 2026 16:04
@skosito
skosito merged commit b256f0f into release/v36 Sep 3, 2026
56 of 58 checks passed
@skosito
skosito deleted the sec/mainnet-v36-vuln-patch branch September 3, 2026 16:13
morde08 pushed a commit that referenced this pull request Sep 3, 2026
…innet/v36) (#4639)

#4637 pinned the squash-merged release/v35 tip (51190f04), which carries
the module-account guard re-gated on the chain's blocked-receive policy:

    delta.Sign() != 0 && k.bankWrapper.BlockedAddr(cosmosAddr)

Live v36.0.6 runs the earlier form, which rejects any module account:

    delta.Sign() != 0 && acct is sdk.ModuleAccountI

ZetaChain's blocked-receive set is a strict subset of its module accounts
(x/fungible, x/crosschain and emissions are deliberately not blocked), so
for an unblocked module account with a non-zero delta the two forms take
different branches -- reject vs. mint/burn. That is a consensus-breaking
difference and must not ship as a v36.0.x patch.

Repins to 3e5f8e53, the commit v36.0.6 was built from, restoring an exact
behavioural match with the deployed binary. The blocked-receive guard is
still a wanted improvement; it needs its own coordinated upgrade.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

no-changelog Skip changelog CI check

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants