PT-2021-18262 · Evm · Evm
Published
2021-05-12
·
Updated
2024-01-30
·
CVE-2021-29511
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
evm versions prior to 0.21.1
evm versions prior to 0.23.1
evm versions prior to 0.24.1
evm versions prior to 0.25.1
evm versions prior to 0.26.1
Description:
The issue is related to the execution of specific EVM opcodes that use
evm core::Memory::copy large for memory operations, which can lead to over-allocation of memory when not needed. This makes it possible for an attacker to perform a denial-of-service attack.Recommendations:
For evm versions prior to 0.21.1, upgrade to version 0.21.1.
For evm versions prior to 0.23.1, upgrade to version 0.23.1.
For evm versions prior to 0.24.1, upgrade to version 0.24.1.
For evm versions prior to 0.25.1, upgrade to version 0.25.1.
For evm versions prior to 0.26.1, upgrade to version 0.26.1 or later.
Fix
Memory Corruption
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Evm