Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3021 | gnark is a fast zk-SNARK library that offers a high-level API to design circuits. In gnark 0.11.0 and earlier, deserialization of Groth16 verification keys allocate excessive memory, consuming a lot of resources and triggering a crash with the error fatal error: runtime: out of memory. |
Github GHSA |
GHSA-cph5-3pgr-c82g | Gnark out-of-memory during deserialization with crafted inputs |
Thu, 31 Oct 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Consensys
Consensys gnark |
|
| CPEs | cpe:2.3:a:consensys:gnark:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Consensys
Consensys gnark |
|
| Metrics |
ssvc
|
Thu, 31 Oct 2024 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | gnark is a fast zk-SNARK library that offers a high-level API to design circuits. In gnark 0.11.0 and earlier, deserialization of Groth16 verification keys allocate excessive memory, consuming a lot of resources and triggering a crash with the error fatal error: runtime: out of memory. | |
| Title | Out-of-memory during deserialization with crafted inputs | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-31T16:53:21.298Z
Reserved: 2024-10-22T17:54:40.958Z
Link: CVE-2024-50354
Updated: 2024-10-31T16:53:16.302Z
Status : Analyzed
Published: 2024-10-31T16:15:05.763
Modified: 2025-09-23T02:00:09.497
Link: CVE-2024-50354
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA