{"id":"GHSA-7f92-rr6w-cq64","aliases":[],"url":"https://o3.security/vulnerability/GHSA-7f92-rr6w-cq64","summary":"Storage corruption due to variables overwritten by re-entrancy locks","details":"### Background\nWhen attempting to use the v0.2.14 release, @pandadefi discovered an issue using the `@nonreentrant` decorator.\n\n### Impact\nReentrancy protection storage slots get allocated to the same slots as storage variables, leading to the corruption of storage variables when using the `@nonreentrant` decorator.\n\n### Patches\nThis issue was fixed in v0.2.15 in #2391, #2379\n\n### Workarounds\nDon't use the `@nonreentrant` decorator in these versions.","published":"2021-08-05T16:57:42Z","modified":"2024-12-02T05:40:46.631779Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"vyper","fixedVersion":"0.2.15"}],"fix":{"url":"https://github.com/vyperlang/vyper/pull/2379","label":"vyperlang/vyper#2379"},"references":[{"type":"WEB","url":"https://github.com/vyperlang/vyper/security/advisories/GHSA-7f92-rr6w-cq64"},{"type":"WEB","url":"https://github.com/vyperlang/vyper/pull/2379"},{"type":"WEB","url":"https://github.com/vyperlang/vyper/pull/2391"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-02T05:40:46.631779Z"}}