GHSA-4v7v-gqf9-ww2g: Pip/vyper vulnerability
Impact When we pass a multi-dimensional array (like [[1, 2], [3, 4]]) as an argument to internal/external functions we get incorrect output. This is due to a stack management issue, because it was assumed that the size of each subtype of an array/struct is 32, which is not always correct.
Example code: python @internal def testinput(arr: int128[2][1], i: int128) -> (int128[2][1], int128): return arr, i
@external def testvalues(arr: int128[2][1], i: int128) -> (int128[2][1], int128): return self.testinput(arr, i)
Please see #2183 for further information
Patches This problem was fixed in #2184, and released as a part of v0.2.6.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/vyperto a version that resolves this vulnerability.Fixed in 0.2.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in v0.2.6Patch #2184
Event History
Frequently Asked Questions
Which Vyper code paths are affected?
The issue affects internal or external function calls that receive multi-dimensional arrays, such as int128[2][1]. The compiler can produce incorrect output because it incorrectly assumes every array or struct subtype occupies 32 bytes.
What version contains the fix?
The fix was released in Vyper v0.2.6 as part of pull request #2184.