The Zcash Foundation has officially announced the release of Zebra 4.4.0, addressing several critical consensus-level security vulnerabilities. According to ChainCatcher, the update is strongly recommended for all node operators to implement immediately. The vulnerabilities include a denial-of-service flaw that could permanently halt new block discovery, errors in block signature operations (sigops) counting leading to consensus discrepancies, abnormal handling of transparent transaction signature hashes, and risks of memory allocation amplification attacks.
The Zcash Foundation warns that some of these vulnerabilities may cause Zebra nodes to accept blocks rejected by zcashd, potentially resulting in chain forks. Without timely updates, nodes could face interruptions in block discovery, consensus forks, and increased resource consumption, with no alternative mitigation solutions currently available.