RewardDistributor:decrementRewards no underflow check needed #143
Labels
bug
Something isn't working
G (Gas Optimization)
sponsor confirmed
Sponsor agrees this is a problem and intends to fix it (OK to use w/ "disagree with severity")
Handle
GiveMeTestEther
Vulnerability details
Impact
Require statement conditions checks that no underflow can happen, therefore we don't need to use safe subtraction (underflow check).
=> Rewrite L278 as: _globals.declaredBalance = _globals.declaredBalance - amount;
Proof of Concept
https://github.com/code-423n4/2021-11-malt/blob/c3a204a2c0f7c653c6c2dda9f4563fd1dc1cecf3/src/contracts/RewardSystem/RewardDistributor.sol#L271
Tools Used
Recommended Mitigation Steps
The text was updated successfully, but these errors were encountered: