• Critical security vulnerabilities in the Radicle network protocol

    From LWN.net@618:250/24 to All on Thu Sep 24 06:40:09 2026

    The Radicle peer-to-peer
    code-collaboration project has disclosed
    two critical vulnerabilities in the network protocol used by Radicle
    nodes. The first flaw is that the network protocol used by Radicle "does not give the confidentiality it was expected to give", which allows anyone who
    can observe the network between two nodes to read the data exchanged. The second
    is that peer authentication is broken and allows impersonation, so an attacker can spoof their Node ID and read private repositories they should not be able to
    read.

    In practice, the two flaws are most useful when they can be exploited
    together: an attacker on the path sees the Node IDs at both ends of a connection, and both are normally on the allow-list. That attacker can read whatever is exchanged while they watch, and can then use a Node ID they saw to fetch the whole repository on demand. The realistic threat is anyone on the path
    between your node and node it syncs with, and no setting or allow-list protects against them.

    We are publishing this before the security update is available. You can act
    on it today, and no fix we release later can undo an exposure that has already happened.

    See the post for workarounds that can be used today; a major update that will be backward-incompatible is underway.

    https://lwn.net/Articles/1096200/
    --- SBBSecho 3.37-Linux
    * Origin: Palantir * palantirbbs.ddns.net * Pensacola, FL * (618:250/24)