CVE-2024-21629 is a high-severity vulnerability affecting the Rust EVM interpreter, specifically its 'evm_project evm' component. It arises from a flawed interaction between the 'record_external_operation' feature and the call stack during CREATE/CREATE2 operations, where a substate commitment can occur even if 'record_external_operation' subsequently fails. This allows smart contracts to commit state changes despite the parent caller receiving a failure indication, impacting library users with custom error-returning 'record_external_operation' implementations. The vulnerability has a CVSS score of 7.5 (High), indicating a network-based attack with low complexity and high integrity impact, but no confidentiality or availability impact. There are no known workarounds, but the issue is patched in release 0.41.1. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, aligning with the typical low attention for a large percentage of CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.41.1CPE matchmatch criteria | cpe:2.3:a:evm_project:evm:*:*:*:*:*:rust:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.