GHSA-2r3x-4mrv-mcxfMedium▾ SunlitVyper: Memory corruption using function calls within tuples / nested calls
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
When performing a function call inside a tuple or as an argument inside another function call, there is a memory corruption issue that occurs because of an incorrect pointer to the the tip of the stack.
Example code:
@internal
def _foo(a: uint256, b: uint256, c: uint256) -> (uint256, uint256, uint256, uint256, uint256):
return 1, a, b, c, 5
@internal
def _foo2() -> uint256:
a: uint256[10] = [6,7,8,9,10,11,12,13,15,16]
return 4
@external
def foo() -> (uint256, uint256, uint256, uint256, uint256):
return self._foo(2, 3, self._foo2())
Please see #2186 for further information
This problem was fixed in #2186, and released as a part of v0.2.6.
vyper < 0.2.6Upgrade to a patched release:
vyper 0.2.6Connected by shared product, vendor, weakness, or advisory.
GHSA-4v7v-gqf9-ww2gMediumVyper: Call stack corruption when passing complex type containing non-base type members as argument
GHSA-vg88-3v92-rjx2MediumVyper: Return inside for loop more than 1 level deep
CVE-2024-24567Medium· 4.8Vyper's raw_call `value=` kwargs not disabled for static and delegate calls
CVE-2023-30629High· 7.5Incorrect success value returned in vyper
CVE-2025-21607LowVyper Does Not Check the Success of Certain Precompile Calls
CVE-2023-32059High· 7.5Vyper vulnerable to incorrect ordering of arguments for kwargs passed to internal calls