Vulnerabilities (CVE)

Filtered by CWE-682
Angry Yack Logo
Total 121 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-45056 1 Matter-labs 1 Zksolc 2024-09-03 N/A 5.9 MEDIUM
zksolc is a Solidity compiler for ZKsync. All LLVM versions since 2015 fold `(xor (shl 1, x), -1)` to `(rotl ~1, x)` if run with optimizations enabled. Here `~1` is generated as an unsigned 64 bits number (`2^64-1`). This number is zero-extended to 256 bits on EraVM target while it should have been sign-extended. Thus instead of producing `roti 2^256 - 1, x` the compiler produces `rotl 2^64 - 1, x`. Analysis has shown that no contracts were affected by the date of publishing this advisory. This ...

Show More