A AegiFlow
MEDIUMCVSS 6.9EPSS 0.5%

CVE-2023-41052

incorrect order of evaluation of side effects for some builtins

Published
2023-09-04
Modified
2026-09-17
EPSS percentile
44%
Aliases
GHSA-4hg4-9mf5-wxxq
Sources
github-advisory

Summary

### Impact The order of evaluation of the arguments of the builtin functions `uint256_addmod`, `uint256_mulmod`, `ecadd` and `ecmul` does not follow source order. • For `uint256_addmod(a,b,c)` and `uint256_mulmod(a,b,c)`, the order is `c,a,b`. • For `ecadd(a,b)` and `ecmul(a,b)`, the order is `b,a`. Note that this behaviour is problematic when the evaluation of one of the arguments produces side effects that other arguments depend on. ### Patches https://github.com/vyperlang/vyper/pull/3583 ### Workarounds When using builtins from the list above, make sure that the arguments of the expression do not produce side effects or, if one does, that no other argument is dependent on those side effects.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIvyper0.3.10

Remediation: Upgrade to 0.3.10 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.