CVE-2022-23066
Summary
| CVE | CVE-2022-23066 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-09 07:15:00 UTC |
| Updated | 2023-02-10 16:38:00 UTC |
| Description | In Solana rBPF versions 0.2.26 and 0.2.27 are affected by Incorrect Calculation which is caused by improper implementation of sdiv instruction. This can lead to the wrong execution path, resulting in huge loss in specific cases. For example, the result of a sdiv instruction may decide whether to transfer tokens or not. The vulnerability affects both integrity and may cause serious availability problems. |
Risk And Classification
Problem Types: CWE-682
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| How a Critical Bug in Solana Network was Detected and Timely Patched | by BlockSec | Jun, 2022 | Medium | MISC | blocksecteam.medium.com | |
| jit: sign-extend the quotient register on sdiv32 (#310) · solana-labs/rbpf@e61e045 · GitHub | MISC | github.com | |
| CVE-2022-23066 | WhiteSource Vulnerability Database | MISC | www.whitesourcesoftware.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: BlockSec
There are currently no legacy QID mappings associated with this CVE.