Solidity compiler bug SOL-2026-5: Memory Byte Array Element Delete Clears Whole Word
Applying ``delete`` to a single element of a ``bytes`` array in memory clears not only that element but the whole 32-byte word starting at the element's location, zeroing up to 31 bytes beyond the element. Affects solc < 0.8.37.
Vuln-watch · relayed from a public source; see Source & attribution below
Summary
Applying `delete to a single element of a bytes` array in memory clears not only that element but the whole 32-byte word starting at the element's location, zeroing up to 31 bytes beyond the element.
Details
Elements of `bytes arrays in memory are packed, each occupying a single byte. When a value is assigned to such an element, the evmasm code generator correctly stores it with a single-byte MSTORE8 instruction. The code path in the evmasm pipeline implementing delete on such an element, however, wrote the zero value with a full-word MSTORE, clearing the 32 bytes starting at the element's location. The bytes following the element within the array were silently zeroed. If the element was within the last 31 bytes of the array's allocation, the write also extended past it into the area where the allocator places the next memory object, clearing the most significant bytes of that object's first word. How many elements are in reach depends on the size of the allocation: arrays created with new bytes(n) or from literals occupy their length rounded up to a multiple of 32 bytes, so only elements falling within the last 31 bytes of that rounded-up area, if any, could be affected. The results of bytes.concat, string.concat, and the abi.encode* functions, on the other hand, are placed by the evmasm pipeline in an allocation of exactly the size of their data, so the next object starts immediately after their last element and each of their last 31 elements is in reach. Assigning zero to an element (b[i] = 0) was not affected, only the delete` operator, and neither were byte arrays in transient storage, storage, or calldata. The bug exists only in the evmasm pipeline. Code compiled via IR is unaffected. Optimizer settings have no influence. The defective code predates the first released version of the compiler.
Affected
- Solidity compiler (solc), solc < 0.8.37
Severity
Medium (upstream rating: "low/medium").
Recommended actions
- Contracts compiled with an affected solc version: check whether the conditions apply to your code; recompile with solc 0.8.37+
- Auditors: add this bug to version-specific checklists
Source & attribution
This 0xCERT advisory summarises Solidity compiler bug SOL-2026-5 (MemoryByteArrayElementDeleteClearsWholeWord) from the Solidity team's bug list: https://blog.soliditylang.org/2026/09/10/memory-byte-array-element-delete-clears-whole-word-bug/.
References
OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.
Published 2026-09-10 · last updated 2026-10-08
curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0167/signed.txt | gpg --verify