<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:44:02 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-197932</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-197932</link>
      <description>EUVD-2026-197932</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-197932</guid>
    </item>
    <item>
      <title>fkie_cve-2024-24564</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-24564</link>
      <description>&lt;p&gt;Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. When using the built-in `extract32(b, start)`, if the `start` index provided has for side effect to update `b`, the byte array to extract `32` bytes from, it could be that some dirty memory is read and returned by `extract32`. This vulnerability is fixed in 0.4.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. When using the built-in `extract32(b, start)`, if the `start` index provided has for side effect to update `b`, the byte array to extract `32` bytes from, it could be that some dirty memory is read and returned by `extract32`. This vulnerability is fixed in 0.4.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-24564</guid>
    </item>
    <item>
      <title>GHSA-4hwq-4cpm-8vmx — Vyper's `extract32` can ready dirty memory</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4hwq-4cpm-8vmx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vyper&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When using the built-in `extract32(b, start)`, if the `start` index provided has for side effect to update `b`, the byte array to extract `32` bytes from, it could be that some dirty memory is read and returned by `extract32`.&lt;/p&gt;
&lt;p&gt;As of v0.4.0 (specifically, commit https://github.com/vyperlang/vyper/commit/3d9c537142fb99b2672f21e2057f5f202cde194f), the compiler will panic instead of generating bytecode.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Before evaluating `start`, the function `Extract32.build_IR` caches only:&lt;/p&gt;
&lt;p&gt;- The pointer in memory/storage to `b`: https://github.com/vyperlang/vyper/blob/10564dcc37756f3d3684b7a91fd8f4325a38c4d8/vyper/builtins/functions.py#L916-L918
- The length of `b`: https://github.com/vyperlang/vyper/blob/10564dcc37756f3d3684b7a91fd8f4325a38c4d8/vyper/builtins/functions.py#L920-L922&lt;/p&gt;
&lt;p&gt;but do not cache the actual content of `b`. This means that if the evaluation of `start` changes `b`&amp;#39;s content and length, an outdated length will be used with the new content when extracting 32 bytes from `b`.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;Calling the function `foo` of the following contract returns `b&amp;#39;uuuuuuuuuuuuuuuuuuuuuuuuuuu\x00\x00789&amp;#39;` meaning that `extract32` accessed some dirty memory.&lt;/p&gt;
&lt;p&gt;```Vyper
var:Bytes[96]&lt;/p&gt;
&lt;p&gt;@internal
def bar() -&amp;gt; uint256:
    self.var = b&amp;#39;uuuuuuuuuuuuuuuuuuuuuuuuuuuuuu&amp;#39;
    self.var = b&amp;#39;&amp;#39;
    return 3&lt;/p&gt;
&lt;p&gt;@external
def foo() -&amp;gt; bytes32:
    self.var = b&amp;#39;abcdefghijklmnopqrstuvwxyz123456789&amp;#39;
    return extract32(self.var, self.bar(), output_type=bytes32)
    # returns b&amp;#39;uuuuuuuuu…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vyper&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When using the built-in `extract32(b, start)`, if the `start` index provided has for side effect to update `b`, the byte array to extract `32` bytes from, it could be that some dirty memory is read and returned by `extract32`.&lt;/p&gt;
&lt;p&gt;As of v0.4.0 (specifically, commit https://github.com/vyperlang/vyper/commit/3d9c537142fb99b2672f21e2057f5f202cde194f), the compiler will panic instead of generating bytecode.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Before evaluating `start`, the function `Extract32.build_IR` caches only:&lt;/p&gt;
&lt;p&gt;- The pointer in memory/storage to `b`: https://github.com/vyperlang/vyper/blob/10564dcc37756f3d3684b7a91fd8f4325a38c4d8/vyper/builtins/functions.py#L916-L918
- The length of `b`: https://github.com/vyperlang/vyper/blob/10564dcc37756f3d3684b7a91fd8f4325a38c4d8/vyper/builtins/functions.py#L920-L922&lt;/p&gt;
&lt;p&gt;but do not cache the actual content of `b`. This means that if the evaluation of `start` changes `b`&amp;#39;s content and length, an outdated length will be used with the new content when extracting 32 bytes from `b`.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;Calling the function `foo` of the following contract returns `b&amp;#39;uuuuuuuuuuuuuuuuuuuuuuuuuuu\x00\x00789&amp;#39;` meaning that `extract32` accessed some dirty memory.&lt;/p&gt;
&lt;p&gt;```Vyper
var:Bytes[96]&lt;/p&gt;
&lt;p&gt;@internal
def bar() -&amp;gt; uint256:
    self.var = b&amp;#39;uuuuuuuuuuuuuuuuuuuuuuuuuuuuuu&amp;#39;
    self.var = b&amp;#39;&amp;#39;
    return 3&lt;/p&gt;
&lt;p&gt;@external
def foo() -&amp;gt; bytes32:
    self.var = b&amp;#39;abcdefghijklmnopqrstuvwxyz123456789&amp;#39;
    return extract32(self.var, self.bar(), output_type=bytes32)
    # returns b&amp;#39;uuuuuuuuu…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4hwq-4cpm-8vmx</guid>
    </item>
    <item>
      <title>gsd-2024-24564</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-24564</link>
      <description>gsd-2024-24564</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-24564</guid>
    </item>
    <item>
      <title>PYSEC-2024-205</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2024-205</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vyper&lt;/p&gt;
&lt;p&gt;Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. When using the built-in `extract32(b, start)`, if the `start` index provided has for side effect to update `b`, the byte array to extract `32` bytes from, it could be that some dirty memory is read and returned by `extract32`. This vulnerability is fixed in 0.4.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vyper&lt;/p&gt;
&lt;p&gt;Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. When using the built-in `extract32(b, start)`, if the `start` index provided has for side effect to update `b`, the byte array to extract `32` bytes from, it could be that some dirty memory is read and returned by `extract32`. This vulnerability is fixed in 0.4.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2024-205</guid>
    </item>
  </channel>
</rss>
