CVE-2024-43366

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Aug 15, 2024
Updated: Aug 19, 2024
CWE ID 835

Summary

CVE-2024-43366 is a vulnerability affecting the zkvyper compiler, used for compiling Vyper smart contracts. In versions 1.3.12 and earlier than 1.5.3, a loophole in LLL IR compilation results in a much later exit condition for a loop. This issue can lead to financial loss or unwanted behavior if the loop body contains the exploited condition. However, common use cases like array iteration are not affected. No contracts were reportedly impacted by this vulnerability, which was rectified in version 1.5.3. To mitigate the risk, it's recommended to upgrade and redeploy affected contracts.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share