GHSA-7f92-rr6w-cq64
Dashboard / Vulnerabilities / GHSA-7f92-rr6w-cq64
GHSA-7f92-rr6w-cq64
Summary: Storage corruption due to variables overwritten by re-entrancy locks
Details: ### Background When attempting to use the v0.2.14 release, @pandadefi discovered an issue using the `@nonreentrant` decorator. ### Impact Reentrancy protection storage slots get allocated to the same slots as storage variables, leading to the corruption of storage variables when using the `@nonreentrant` decorator. ### Patches This issue was fixed in v0.2.15 in #2391, #2379 ### Workarounds Don't use the `@nonreentrant` decorator in these versions.
References: https://github.com/vyperlang/vyper/security/advisories/GHSA-7f92-rr6w-cq64, https://github.com/vyperlang/vyper/pull/2379, https://github.com/vyperlang/vyper/pull/2391
Affected packages
Package
Name: vyper
Purl: pkg:pypi/vyper
Affected ranges
Type: ECOSYSTEM
Events:
