CVE-2021-29511
Status: ModifiedMedium (6.5)—
evm is a pure Rust implementation of Ethereum Virtual Machine. Prior to the patch, when executing specific EVM opcodes related to memory operations that use `evm_core::Memory::copy_large`, the `evm` crate can over-allocate memory when it is not needed, making it possible for an attacker to perform denial-of-service attack. The flaw was corrected in commit `19ade85`. Users should upgrade to `==0.21.1, ==0.23.1, ==0.24.1, ==0.25.1, >=0.26.1`. There are no workarounds. Please upgrade your `evm` crate version.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Base score: 6.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.28%
- Percentile among all scored CVEs: 69
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-770
- CWE-787
References
- https://crates.io/crates/evm
- https://github.com/rust-blockchain/evm/commit/19ade858c430ab13eb562764a870ac9f8506f8dd
- https://github.com/rust-blockchain/evm/security/advisories/GHSA-4jwq-572w-4388
- https://crates.io/crates/evm
- https://github.com/rust-blockchain/evm/commit/19ade858c430ab13eb562764a870ac9f8506f8dd
- https://github.com/rust-blockchain/evm/security/advisories/GHSA-4jwq-572w-4388
Raw JSON (NVD)
Show
{
"id": "CVE-2021-29511",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "rust-blockchain",
"product": "evm",
"versions": [
{
"status": "affected",
"version": "< 0.21.1"
},
{
"status": "affected",
"version": "= 0.22.0"
},
{
"status": "affected",
"version": "= 0.23.0"
},
{
"status": "affected",
"version": "= 0.24.0"
},
{
"status": "affected",
"version": "= 0.25.0"
}
]
}
]
}
],
"published": "2021-05-12T18:15:08.527",
"references": [
{
"url": "https://crates.io/crates/evm",
"tags": [
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/rust-blockchain/evm/commit/19ade858c430ab13eb562764a870ac9f8506f8dd",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/rust-blockchain/evm/security/advisories/GHSA-4jwq-572w-4388",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://crates.io/crates/evm",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/rust-blockchain/evm/commit/19ade858c430ab13eb562764a870ac9f8506f8dd",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/rust-blockchain/evm/security/advisories/GHSA-4jwq-572w-4388",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-770"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-787"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "evm is a pure Rust implementation of Ethereum Virtual Machine. Prior to the patch, when executing specific EVM opcodes related to memory operations that use `evm_core::Memory::copy_large`, the `evm` crate can over-allocate memory when it is not needed, making it possible for an attacker to perform denial-of-service attack. The flaw was corrected in commit `19ade85`. Users should upgrade to `==0.21.1, ==0.23.1, ==0.24.1, ==0.25.1, >=0.26.1`. There are no workarounds. Please upgrade your `evm` crate version."
},
{
"lang": "es",
"value": "evm es una implementación pura de Rust de Ethereum Virtual Machine. Anterior al parche, cuando se ejecutan códigos de operación EVM específicos relacionados con operaciones de memoria que usan la función \"evm_core::Memory::copy_large\", la crate \"evm\" puede sobreasignar memoria cuando no es necesaria, haciendo posible a un atacante llevar a cabo un ataque de denegación de servicio. El fallo fue corregido en el commit \"19ade85\". Los usuarios deberían actualizar a \"==0.21.1, ==0.23.1, ==0.24.1, ==0.25.1, )=0.26.1\". No existen soluciones alternativas. Por favor Actualice su versión de crate \"evm\""
}
],
"lastModified": "2026-06-17T03:47:48.350",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:evm_project:evm:*:*:*:*:*:rust:*:*",
"vulnerable": true,
"matchCriteriaId": "BC526576-249B-4C0E-AAF0-85614F8F42E1",
"versionEndIncluding": "0.21.0"
},
{
"criteria": "cpe:2.3:a:evm_project:evm:0.22.0:*:*:*:*:rust:*:*",
"vulnerable": true,
"matchCriteriaId": "F18F86B1-8BED-4A6E-91A9-BB77819A3A6C"
},
{
"criteria": "cpe:2.3:a:evm_project:evm:0.23.0:*:*:*:*:rust:*:*",
"vulnerable": true,
"matchCriteriaId": "07E8CA2D-3CF8-4069-9F3F-D9CB0E6FB182"
},
{
"criteria": "cpe:2.3:a:evm_project:evm:0.24.0:*:*:*:*:rust:*:*",
"vulnerable": true,
"matchCriteriaId": "E70A1FF9-F6EE-486B-9E91-A6548E624A02"
},
{
"criteria": "cpe:2.3:a:evm_project:evm:0.25.0:*:*:*:*:rust:*:*",
"vulnerable": true,
"matchCriteriaId": "4D49607D-993F-44D7-A144-68B4939B6B2D"
},
{
"criteria": "cpe:2.3:a:evm_project:evm:0.26.0:*:*:*:*:rust:*:*",
"vulnerable": true,
"matchCriteriaId": "2C81A330-9BAF-4CC7-BA5C-69164C4A6189"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}