Junglewise Threat Intelligence

CVE-2022-35915: OpenZeppelin Contracts ERC165Checker unbounded gas consumption

CVE-2022-35915 · Severity: low · CVSS 3.1 · Published 2022-08-14

Technologies: OpenZeppelin Contracts, @openzeppelin/contracts (npm), OpenZeppelin Contracts Upgradeable, @openzeppelin/contracts-upgradeable (npm). Vendors: OpenZeppelin, npm.

Executive brief

OpenZeppelin Contracts is a widely-used library for Ethereum smart contract development. A flaw in the ERC165Checker component allows a malicious target contract to consume excessive gas during interface compatibility checks, potentially causing transaction failures or denial of service for applications relying on these checks.

Technical details

The vulnerability exists in the ERC165Checker utility, which is used to query whether a target contract supports a specific EIP-165 interface via the supportsInterface function. An attacker controlling the target contract can craft a malicious implementation that returns large amounts of data, causing unbounded gas consumption during the query, violating the assumption that such checks have bounded cost. The attack is network-accessible and requires no authentication or user interaction; the attacker must control or manipulate the target contract being queried. This can lead to out-of-gas exceptions and denial of service. The issue has been patched in Contracts v4.7.2 and Contracts Upgradeable v4.7.2.

Affected products

  • OpenZeppelin Contracts 2.0.0 to 4.7.1
  • OpenZeppelin Contracts Upgradeable 3.2.0 to 4.7.1
  • OpenZeppelin openzeppelin-eth 2.0.0 to 2.2.0
  • OpenZeppelin openzeppelin-solidity 2.0.0 to 4.6.0

Timeline

  • 2022-07-28: disclosed: Advisory published by OpenZeppelin
  • 2022-08-14: patched: Fix released in v4.7.2 and Contracts Upgradeable v4.7.2

References

Related threats