GHSA-2r3x-4mrv-mcxf: Vyper: Memory corruption using function calls within tuples / nested calls
When performing a function call inside a tuple or as an argument inside another function call, there is a memory corruption issue that occurs because of an incorrect pointer to the the tip of the stack.
Example code:
@internal
def _foo(a: uint256, b: uint256, c: uint256) -> (uint256, uint256, uint256, uint256, uint256):
return 1, a, b, c, 5
@internal
def _foo2() -> uint256:
a: uint256[10] = [6,7,8,9,10,11,12,13,15,16]
return 4
@external
def foo() -> (uint256, uint256, uint256, uint256, uint256):
return self._foo(2, 3, self._foo2())
Please see #2186 for further information
References
Code Behaviors & Features
Detect and mitigate GHSA-2r3x-4mrv-mcxf with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →