Skip to content

Memory over-allocation in evm crate

Critical
sorpaas published GHSA-4jwq-572w-4388 May 11, 2021

Package

cargo evm-core (Rust)

Affected versions

<=0.21.0, ==0.22.0, ==0.23.0, ==0.24.0, ==0.25.0, ==0.26.0

Patched versions

==0.21.1, ==0.23.1, ==0.24.1, ==0.25.1, >=0.26.1

Description

Impact

Prior to the patch, when executing specific EVM opcodes related to memory operations that use evm_core::Memory::copy_large, the crate can over-allocate memory when it is not needed, making it possible for an attacker to perform denial-of-service attack.

Patches

The flaw was corrected in commit 19ade85. Users should upgrade to ==0.21.1, ==0.23.1, ==0.24.1, ==0.25.1, >=0.26.1.

Workarounds

None. Please upgrade your evm crate version

References

Fix commit: 19ade85

For more information

If you have any questions or comments about this advisory:

Severity

Critical

CVE ID

CVE-2021-29511

Weaknesses

No CWEs