GHSA-cx2q-hfxr-rj97

    Dashboard / Vulnerabilities / GHSA-cx2q-hfxr-rj97

    GHSA-cx2q-hfxr-rj97

    Published: 26 Sept 2023Last Modified: 19 Nov 2024

    Summary: Vyper's `_abi_decode` input not validated in complex expressions

    Details: ### Impact `_abi_decode()` does not validate input when it is nested in an expression. the following example gets correctly validated (bounds checked): ```vyper x: int128 = _abi_decode(slice(msg.data, 4, 32), int128) ``` however, the following example is not bounds checked ```vyper @external def abi_decode(x: uint256) -> uint256: a: uint256 = convert(_abi_decode(slice(msg.data, 4, 32), (uint8)), uint256) + 1 return a # abi_decode(256) returns: 257 ``` the issue can be triggered by constructing an example where the output of `_abi_decode` is not internally passed to `make_setter` (an internal codegen routine) or other input validating routine. ### Patches https://github.com/vyperlang/vyper/pull/3626 ### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_ ### References _Are there any links users can visit to find out more?_

    Affected packages

    Package

    Name: vyper

    Purl: pkg:pypi/vyper

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0.3.4
    Fixed -0.3.10

    Affected versions

    0.3.10rc1
    0.3.10rc2
    0.3.10rc3
    0.3.10rc4
    0.3.10rc5
    0.3.4
    0.3.5
    0.3.6
    0.3.7
    0.3.8
    0.3.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-cx2q-hfxr-rj97 | CVE-DB