-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 0xCERT Security Advisory 0xCERT-2026-0164 ============================================================ Advisory-ID: 0xCERT-2026-0164 Severity: Medium Published: 2026-07-09T00:00:00.000Z Updated: 2026-10-08T22:46:33.758Z Chains: Ethereum URL: https://www.0xcert.com/advisory/0xCERT-2026-0164 Title: Solidity compiler bug SOL-2026-3: Inheritance Order Reversal On Storage End Warning Summary - ------- Emitting a warning about storage base location being too close to the storage end unintentionally reversed the ``linearizedBaseContracts`` annotation, possibly leading to miscompilation due to reversing the order in which inheritance is resolved. Affects 0.8.29 ≤ solc < 0.8.36. Details - ------- Summary Emitting a warning about storage base location being too close to the storage end unintentionally reversed the ``linearizedBaseContracts`` annotation, possibly leading to miscompilation due to reversing the order in which inheritance is resolved. Details When the compiler detects that a custom layout specifier puts contract's static storage area too close to the end of the address space, it emits a warning. To make the warning more useful, the compiler tries to point at the last storage variable in that area. For this reason it walks the linearized inheritance hierarchy in reverse (from the least to the most derived). The list is calculated once and stored in an AST annotation called ``linearizedBaseContracts``. The direct cause of the bug was the fact that the code that reverses the list was doing it in place rather than on a copy, modifying the annotation. This effectively reversed the order of base contracts seen by any component that runs after layout checks: later phases of analysis, AST export, code generator, SMTChecker, etc. The observable effect was a reversed order of state variable initialization, constructor invocation, virtual function/modifier resolution, leading either to miscompilations or internal compiler errors, depending on the specific usage. Since the source of the bug was in the analysis stage, it was independent of the codegen pipeline or optimizer settings. The main condition necessary to trigger the bug was the presence of the warning in the output. The other is presence of language constructs whose evaluation depends on the inheritance order. While potential effects are very serious, this requirement excludes the vast majority of contracts as intentionally placing the storage variables in the last 2**64 slots is highly discouraged, which was actually the main reason for adding this warning. Affected - - Solidity compiler (solc), 0.8.29 ≤ solc < 0.8.36 Severity Medium (upstream rating: "medium"). Recommended actions - - Contracts compiled with an affected solc version: check whether the conditions apply to your code; recompile with solc 0.8.36+ - - Auditors: add this bug to version-specific checklists Source & attribution This 0xCERT advisory summarises Solidity compiler bug SOL-2026-3 (InheritanceOrderReversalOnStorageEndWarning) from the Solidity team's bug list: https://blog.soliditylang.org/2026/07/09/inheritance-order-reversal-on-storage-end-warning-bug/. References - ---------- - - https://blog.soliditylang.org/2026/07/09/inheritance-order-reversal-on-storage-end-warning-bug/ - - https://github.com/ethereum/solidity/blob/develop/docs/bugs.json Verify with the 0xCERT OpenPGP key: https://www.0xcert.com/pgp.asc Fingerprint: 5F94 3ED1 1E50 CF31 2128 C493 CCC7 D9EC 9415 723D -----BEGIN PGP SIGNATURE----- wrsEARYKAG0FgmrIRioJEDe9Tbcr+ZxrRRQAAAAAABwAIHNhbHRAbm90YXRp b25zLm9wZW5wZ3Bqcy5vcme9dmutdjIwIJgymQYgLKonBGikvw+7m8rEbgJC 0WFOKhYhBGCkkFZbJcT5QWu27ze9Tbcr+ZxrAADYXgEAlb2OJ4IWpcyaLoM4 gBVm/0LEVzw+/uvoQbvOclK44mUA/itJaJqfA/ztcv4sannABTIYuVd3Rf33 MRUjgIMSfEIN =E4QJ -----END PGP SIGNATURE-----