PT-2022-15825 · Solana · Solana Rbpf
Blocksec
·
Published
2022-05-09
·
Updated
2023-02-10
·
CVE-2022-23066
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Solana rBPF versions 0.2.26 through 0.2.27
Description
The issue is caused by an improper implementation of the sdiv instruction, leading to incorrect calculations. This can result in the wrong execution path, potentially causing significant losses in specific cases, such as deciding whether to transfer tokens or not. The problem affects both integrity and may cause serious availability issues.
Recommendations
For versions 0.2.26 and 0.2.27, consider disabling the sdiv instruction temporarily until a patch is available to prevent potential incorrect calculations and execution paths.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Solana Rbpf