PT-2024-28059 · Unknown · Zksync Era

Hedgar2017

·

Published

2024-06-28

·

Updated

2024-07-01

·

CVE-2024-38533

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ZKsync Era versions prior to 1.5.0
Description ZKsync Era is a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. The issue arises from possible invalid stack access due to the addresses used to access the stack not properly being converted to cells.
Recommendations For versions prior to 1.5.0, update to version 1.5.0 to resolve the issue.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2024-38533
GHSA-Q7PG-6JH9-87GV

Affected Products

Zksync Era