CVE-2024-38533

MEDIUM

ZKsync Era <1.5.0 - Buffer Overflow

Title source: llm
STIX 2.1

Description

ZKsync Era is a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. There is possible invalid stack access due to the addresses used to access the stack not properly being converted to cells. This issue has been patched in version 1.5.0.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0026
EPSS Percentile 17.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-787
Status published
Products (1)
matter-labs/era-compiler-vyper < 1.5.0
Published Jun 28, 2024
Tracked Since Feb 18, 2026