Bug 2366634 (CVE-2025-47285)
| Summary: | CVE-2025-47285 vyper: Vyper: Zero-Length Bytestring Side-Effect Skipping | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A vulnerability has been identified in the Vyper programming language. This flaw can lead to the unintended omission of side effects during string concatenation operations when zero-length bytestring arguments are used. This could result in unexpected or incorrect program behavior, particularly in smart contract logic where side effects are critical for maintaining state and executing intended actions.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2366742, 2366743 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2025-05-15 18:01:35 UTC
|