GHSA-4v7v-gqf9-ww2g: Vyper: Call stack corruption when passing complex type containing non-base type members as argument
When we pass a multi-dimensional array (like [[1, 2], [3, 4]]) as an argument to internal/external functions we get incorrect output. This is due to a stack management issue, because it was assumed that the size of each subtype of an array/struct is 32, which is not always correct.
Example code:
@internal
def test_input(arr: int128[2][1], i: int128) -> (int128[2][1], int128):
return arr, i
@external
def test_values(arr: int128[2][1], i: int128) -> (int128[2][1], int128):
return self.test_input(arr, i)
Please see #2183 for further information
References
- github.com/advisories/GHSA-4v7v-gqf9-ww2g
- github.com/vyperlang/vyper/commit/0be02b7331e8febe79d5a4218829c72e30417a29
- github.com/vyperlang/vyper/issues/2183
- github.com/vyperlang/vyper/pull/2184
- github.com/vyperlang/vyper/releases/tag/v0.2.6
- github.com/vyperlang/vyper/security/advisories/GHSA-4v7v-gqf9-ww2g
Code Behaviors & Features
Detect and mitigate GHSA-4v7v-gqf9-ww2g with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →