Medium severity6.5NVD Advisory· Published Jan 14, 2022· Updated Jun 17, 2026
CVE-2022-21685
CVE-2022-21685
Description
Frontier is Substrate's Ethereum compatibility layer. Prior to commit number 8a93fdc6c9f4eb1d2f2a11b7ff1d12d70bf5a664, a bug in Frontier's MODEXP precompile implementation can cause an integer underflow in certain conditions. This will cause a node crash for debug builds. For release builds (and production WebAssembly binaries), the impact is limited as it can only cause a normal EVM out-of-gas. Users who do not use MODEXP precompile in their runtime are not impacted. A patch is available in pull request #549.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pallet-evm-precompile-modexpcrates.io | <= 1.0.0 | — |
Affected products
2- Range: < 8a93fdc
Patches
Vulnerability mechanics
References
5- github.com/paritytech/frontier/commit/8a93fdc6c9f4eb1d2f2a11b7ff1d12d70bf5a664nvdPatchThird Party AdvisoryWEB
- github.com/paritytech/frontier/pull/549nvdPatchThird Party AdvisoryWEB
- github.com/paritytech/frontier/security/advisories/GHSA-cjg2-2fjg-fph4nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-cjg2-2fjg-fph4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-21685ghsaADVISORY
News mentions
0No linked articles in our index yet.