Back to Database
Status published
Medium
CVE-2024-38533
ZKsync Era invalid stack addressing conversion
Vulnerability Description
ZKsync Era is a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. There is possible invalid stack access due to the addresses used to access the stack not properly being converted to cells. This issue has been patched in version 1.5.0.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-38533
Credits & Attribution
No credits recorded in the NVD database.
References
More from matter-labs
View All →CVE-2024-45056
`fold (xor (shl 1, x), -1) -> (rotl ~1, x)` misoptimization in zksolc
Medium
5.9
CVE-2024-43366
zkvyper ignored loop range bounds
High
7.5
CVE-2024-35229
ZKsync Era evaluation order of Yul function arguments
Medium
5.3
CVE-2024-34704
era-compiler-solidity contains a `xor(zext(cmp), -1)` misoptimization
Medium
5.9
CVE-2023-46232
era-compiler-vyper First Immutable Variable Initialization vulnerability
Medium
5.3
Affected Vendor
matter-labs
View all reports →Affected Software
era-compiler-vyper
Vulnerable Versions:
< 1.5.0
Timeline
Official Publish:
June 28th, 2024
Last Modified:
August 2nd, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N