Executive brief
Vyper is a Python-like programming language for writing smart contracts on Ethereum. A code generation defect allows attackers to trigger out-of-bounds array access when a dynamic array appears on both sides of an assignment, potentially corrupting memory and causing contract misbehavior or data loss.
Technical details
This is a code generation (codegen) vulnerability affecting Vyper's handling of DynArray (dynamic array) assignments. When a DynArray is used on both the left-hand side (LHS) and right-hand side (RHS) of an assignment, the compiler writes the array's length metadata before validating bounds, leading to out-of-bounds memory access. The vulnerability affects operations like `a = [a[0], a[1], a[2]]` on empty or smaller arrays, including combinations with append() and pop() methods. No special privileges or network access required—any contract code compiled with vulnerable versions will exhibit the flaw. The issue was patched in version 0.3.8 (commit 4f8289a).
Affected products
- Vyper Vyper < 0.3.8
Timeline
- 2023-05-11: disclosed
- 2023-05-12: patched: Fixed in version 0.3.8 (commit 4f8289a)