Junglewise Threat Intelligence

CVE-2025-54070: OpenZeppelin Contracts out-of-bounds memory access in Bytes.lastIndexOf

CVE-2025-54070 · Severity: low · CVSS 3.1 · Published 2025-07-17

Technologies: OpenZeppelin Contracts, @openzeppelin/contracts (npm), OpenZeppelin Contracts Upgradeable, @openzeppelin/contracts-upgradeable (npm). Vendors: OpenZeppelin, npm.

Executive brief

OpenZeppelin Contracts is a widely-used library providing secure, audited smart contract components for blockchain applications. The Bytes library's lastIndexOf function contains a memory safety flaw that can read outside buffer boundaries when processing empty buffers with certain position arguments. This could cause applications to receive invalid memory values, leading to unexpected behavior, denial of service through out-of-gas conditions, or logic errors in dependent code that doesn't validate returned indices.

Technical details

The vulnerability is a bounded out-of-bounds memory read (CWE-125) in the lastIndexOf(bytes,byte,uint256) function within Solidity's Bytes library. When the buffer is empty (length == 0) and the position argument is not type(uint256).max, the function accesses uninitialized memory at offset buffer + 0x20 + pos instead of returning the expected sentinel value. If memory at that location matches the search byte pattern, the function returns an invalid index pointing outside the buffer bounds, rather than type(uint256).max as documented. Callers that use the returned index for subsequent memory access without bounds checking could trigger reverts or undefined behavior. The vulnerability affects versions 5.2.0 through 5.3.x and is fixed in version 5.4.0.

Affected products

  • OpenZeppelin Contracts 5.2.0–5.3.x
  • OpenZeppelin Contracts Upgradeable 5.2.0–5.3.x

Timeline

  • 2025-07-17: disclosed
  • 2025-07-17: patched: Fixed in version 5.4.0

References

Related threats