GHSA-2r3x-4mrv-mcxf: Out-of-bounds Read
Impact When performing a function call inside a tuple or as an argument inside another function call, there is a memory corruption issue that occurs because of an incorrect pointer to the the tip of the stack.
Example code: python @internal def foo(a: uint256, b: uint256, c: uint256) -> (uint256, uint256, uint256, uint256, uint256): return 1, a, b, c, 5
@internal def foo2() -> uint256: a: uint256[10] = [6,7,8,9,10,11,12,13,15,16] return 4
@external def foo() -> (uint256, uint256, uint256, uint256, uint256): return self.foo(2, 3, self.foo2())
Please see #2186 for further information
Patches This problem was fixed in #2186, and released as a part of v0.2.6.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/vyperto a version that resolves this vulnerability.Fixed in 0.2.6 - Upgrade
Upgrade
Vyperto a version that resolves this vulnerability.Fixed in 0.2.6
Event History
Frequently Asked Questions
Which release includes the fix?
The fix was released in Vyper v0.2.6 as part of pull request #2186.