The GetVault derivative contract implements the poolMatchesOracle() function, which is used by deposit(), withdraw() and rebalance() functions.
The poolMatchesOracle() function checks that the pool price isn't manipulated using a Uniswap V3 pool.
The function queries the pool to fetch the sqrtPriceX96 and does the following calculation:
The main issue here is that the multiplications in the expression sqrtPriceX96 (uint(sqrtPriceX96)) (1e18) may eventually overflow. This case is taken into consideration by the implementation of the OracleLibrary.getQuoteAtTick function which is part of the Uniswap V3 periphery set of contracts.
Note that this implementation guards against different numerical issues. In particular, the if in line 58 checks for a potential overflow of sqrtRatioX96 and switches the implementation to avoid the issue.
Tools Used
Manual Review
Recommended Mitigation Steps
The poolPrice function can delegate the calculation directly to the OracleLibrary.getQuoteAtTick function of the v3-periphery package:
Lines of code
https://github.com/code-423n4/2023-08-goodentry/blob/main/contracts/GeVault.sol#L367-L378
Vulnerability details
Impact
Overflow.
Proof of Concept
The GetVault derivative contract implements the
poolMatchesOracle()
function, which is used bydeposit()
,withdraw()
andrebalance()
functions. ThepoolMatchesOracle()
function checks that the pool price isn't manipulated using a Uniswap V3 pool. The function queries the pool to fetch the sqrtPriceX96 and does the following calculation:solidity priceX8 = (priceX8 * uint(sqrtPriceX96 / 2 ** 12) ** 2 * 1e8) / 2 ** 168;
The main issue here is that the multiplications in the expression sqrtPriceX96 (uint(sqrtPriceX96)) (1e18) may eventually overflow. This case is taken into consideration by the implementation of the OracleLibrary.getQuoteAtTick function which is part of the Uniswap V3 periphery set of contracts.
Note that this implementation guards against different numerical issues. In particular, the if in line 58 checks for a potential overflow of sqrtRatioX96 and switches the implementation to avoid the issue.
Tools Used
Manual Review
Recommended Mitigation Steps
The poolPrice function can delegate the calculation directly to the OracleLibrary.getQuoteAtTick function of the v3-periphery package:
Assessed type
Uniswap