Skip to content
Latest alertgo-ethereum v1.17.8 security release fixes p2p DoS issues and a STUN-response node crash
0xCERT
All advisories
Medium0xCERT-2026-0213·

Solidity compiler bug SOL-2026-2: Unsound Spill In Mutual Recursion

Local variables of a function involved in mutual recursion may spuriously be moved to fixed memory offsets and overwritten across recursive calls. Affects 0.7.2 ≤ solc < 0.8.36.

Vuln-watch · relayed from a public source; see Source & attribution below

Affected chainsEthereum

Summary

Local variables of a function involved in mutual recursion may spuriously be moved to fixed memory offsets and overwritten across recursive calls.

Details

To work around the 16-slot stack access limit of the EVM, the IR-based code generator can move local variables of stack-too-deep functions to fixed memory offsets. This relocation is unsound for recursive functions: a fixed offset would be shared by all activations of the function, so a recursive call would overwrite the caller's value. The stack limit evader therefore must not relocate variables of functions that are part of a recursive call chain. To this end, the call graph was searched for cycles using a path-based depth-first search that, once a function had been fully explored and popped from the search path, short-circuited on it on any later visit. As a result, a function shared between several intersecting cycles could be reached first through a path that did not yet close a cycle through it, get marked as finished, and then be skipped when a later path would have revealed that it does lie on a cycle. Such a function was misclassified as non-recursive. When a misclassified function was complex enough for the stack limit evader to relocate some of its variables, those variables were moved to fixed memory offsets and silently corrupted on recursion, producing wrong results rather than a compile-time error. Triggering the bug requires the IR pipeline, a set of mutually recursive functions whose call graph contains intersecting cycles, at least one of the functions in an undetected part of a cycle being complex enough to require relocation to memory, and an unfortunate processing order of the functions (which depends on the hashes of their Yul names). It is independent of whether the optimizer is enabled.

Affected

  • Solidity compiler (solc), 0.7.2 ≤ solc < 0.8.36

Severity

Medium (upstream rating: "medium").

Recommended actions

  • Contracts compiled with an affected solc version: check whether the conditions apply to your code; recompile with solc 0.8.36+
  • Auditors: add this bug to version-specific checklists

Source & attribution

This 0xCERT advisory summarises Solidity compiler bug SOL-2026-2 (UnsoundSpillInMutualRecursion) from the Solidity team's bug list: https://blog.soliditylang.org/2026/07/09/unsound-spill-in-mutual-recursion-bug/.

OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.

Published 2026-07-09 · last updated 2026-10-08

curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0213/signed.txt | gpg --verify