PT-2022-15825 · Solana · Solana Rbpf

Blocksec

·

Published

2022-05-09

·

Updated

2023-02-10

·

CVE-2022-23066

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Solana rBPF versions 0.2.26 through 0.2.27
Description The issue is caused by an improper implementation of the sdiv instruction, leading to incorrect calculations. This can result in the wrong execution path, potentially causing significant losses in specific cases, such as deciding whether to transfer tokens or not. The problem affects both integrity and may cause serious availability issues.
Recommendations For versions 0.2.26 and 0.2.27, consider disabling the sdiv instruction temporarily until a patch is available to prevent potential incorrect calculations and execution paths. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23066
GHSA-9QMM-4MFR-R3WJ

Affected Products

Solana Rbpf