PT-2021-18262 · Evm · Evm

Published

2021-05-12

·

Updated

2024-01-30

·

CVE-2021-29511

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: evm versions prior to 0.21.1 evm versions prior to 0.23.1 evm versions prior to 0.24.1 evm versions prior to 0.25.1 evm versions prior to 0.26.1
Description: The issue is related to the execution of specific EVM opcodes that use evm core::Memory::copy large for memory operations, which can lead to over-allocation of memory when not needed. This makes it possible for an attacker to perform a denial-of-service attack.
Recommendations: For evm versions prior to 0.21.1, upgrade to version 0.21.1. For evm versions prior to 0.23.1, upgrade to version 0.23.1. For evm versions prior to 0.24.1, upgrade to version 0.24.1. For evm versions prior to 0.25.1, upgrade to version 0.25.1. For evm versions prior to 0.26.1, upgrade to version 0.26.1 or later.

Fix

Memory Corruption

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-29511
GHSA-4JWQ-572W-4388

Affected Products

Evm