XRPL Node Operators Urged to Update to Version 3.2.1 Immediately
Ripple's Director of Development, Vijay Khanna, has notified XRP Ledger node operators of the release of XRPL version 3.2.1, which contains a critical fix for the network. This update addresses a "manifest flood" attack that was observed in the network on July 31st.
Previously, nodes would accept, store, and relay an unlimited number of manifests from unknown validator keys. Version 3.2.1 implements four key restrictions to prevent such flooding:
- A manifest size limit, rejecting any manifest larger than expected.
- An inbound limit, where incoming packets exceeding a threshold are dropped instead of disconnecting the peer.
- An outbound limit, capping the manifest packet size in welcome messages to new peers.
- A caching limit, rejecting new unknown keys after 100 are stored.
Additionally, manifests from unknown keys are no longer saved to disk, preventing the flood from persisting after a node restart. Node operators are strongly urged to update to XRPL 3.2.1, wait briefly to ensure the process is running, and then restart the xrpld service. This release enhances validator manifest security by rejecting oversized objects early, limiting processing and storage of untrusted data, and preventing untrusted information from entering permanent storage.
cryptonews.ruВчора 09:40