CVE-2022-21685
Summary
| CVE | CVE-2022-21685 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-14 17:15:00 UTC |
| Updated | 2022-01-21 20:40:00 UTC |
| Description | Frontier is Substrate's Ethereum compatibility layer. Prior to commit number `8a93fdc6c9f4eb1d2f2a11b7ff1d12d70bf5a664`, a bug in Frontier's MODEXP precompile implementation can cause an integer underflow in certain conditions. This will cause a node crash for debug builds. For release builds (and production WebAssembly binaries), the impact is limited as it can only cause a normal EVM out-of-gas. Users who do not use MODEXP precompile in their runtime are not impacted. A patch is available in pull request #549. |
Risk And Classification
Problem Types: CWE-191
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Handle 0 exponent with fudged length correctly in ModExp by notlesh · Pull Request #549 · paritytech/frontier · GitHub | MISC | github.com | |
| Handle 0 exponent with fudged length correctly in ModExp (#549) · paritytech/frontier@8a93fdc · GitHub | MISC | github.com | |
| Integer underflow in the MODEXP precompile · Advisory · paritytech/frontier · GitHub | CONFIRM | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.