VDB
Sign up
MEDIUM

GHSA-773q-5334-5gf9

Memory over-allocation in evm-core

Details

Prior to the patch, when executing specific EVM opcodes related to memory operations that use `evm_core::Memory::copy_large`, the crate can over-allocate memory when it is not needed, making it possible for an attacker to perform denial-of-service attack.

The flaw was corrected in commit `19ade85`.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/evm-core
Introduced in: 0.26.0Fixed in: 0.26.1

Upgrade evm-core to 0.26.1 or newer (ecosystem crates.io).

crates.io/evm-core
Introduced in: 0.25.0Fixed in: 0.25.1

Upgrade evm-core to 0.25.1 or newer (ecosystem crates.io).

crates.io/evm-core
Introduced in: 0.24.0Fixed in: 0.24.1

Upgrade evm-core to 0.24.1 or newer (ecosystem crates.io).

crates.io/evm-core
Introduced in: 0.23.0Fixed in: 0.23.1

Upgrade evm-core to 0.23.1 or newer (ecosystem crates.io).

crates.io/evm-core
Introduced in: 0Fixed in: 0.21.1

Upgrade evm-core to 0.21.1 or newer (ecosystem crates.io).

References