{"api_version":"1","generated_at":"2026-07-23T14:33:18+00:00","cve":"CVE-2022-23066","urls":{"html":"https://cve.report/CVE-2022-23066","api":"https://cve.report/api/cve/CVE-2022-23066.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-23066","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-23066"},"summary":{"title":"CVE-2022-23066","description":"In Solana rBPF versions 0.2.26 and 0.2.27 are affected by Incorrect Calculation which is caused by improper implementation of sdiv instruction. This can lead to the wrong execution path, resulting in huge loss in specific cases. For example, the result of a sdiv instruction may decide whether to transfer tokens or not. The vulnerability affects both integrity and may cause serious availability problems.","state":"PUBLIC","assigner":"vulnerabilitylab@whitesourcesoftware.com","published_at":"2022-05-09 07:15:00","updated_at":"2023-02-10 16:38:00"},"problem_types":["CWE-682"],"metrics":[],"references":[{"url":"https://blocksecteam.medium.com/how-a-critical-bug-in-solana-network-was-detected-and-timely-patched-a701870e1324","name":"https://blocksecteam.medium.com/how-a-critical-bug-in-solana-network-was-detected-and-timely-patched-a701870e1324","refsource":"MISC","tags":[],"title":"How a Critical Bug in Solana Network was Detected and Timely Patched | by BlockSec | Jun, 2022 | Medium","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"https://github.com/solana-labs/rbpf/commit/e61e045f8c244de978401d186dcfd50838817297","name":"https://github.com/solana-labs/rbpf/commit/e61e045f8c244de978401d186dcfd50838817297","refsource":"MISC","tags":[],"title":"jit: sign-extend the quotient register on sdiv32 (#310) · solana-labs/rbpf@e61e045 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.whitesourcesoftware.com/vulnerability-database/CVE-2022-23066","name":"https://www.whitesourcesoftware.com/vulnerability-database/CVE-2022-23066","refsource":"MISC","tags":[],"title":"CVE-2022-23066 | WhiteSource Vulnerability Database","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-23066","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23066","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"BlockSec","lang":""}],"nvd_cpes":[{"cve_year":"2022","cve_id":"23066","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"solana","cpe5":"rbpf","cpe6":"0.2.26","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"23066","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"solana","cpe5":"rbpf","cpe6":"0.2.27","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"vulnerabilitylab@whitesourcesoftware.com","DATE_PUBLIC":"2022-05-08T14:15:00.000Z","ID":"CVE-2022-23066","STATE":"PUBLIC","TITLE":"Solana rBPF - Incorrect Calculation in sdiv instruction"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"rbpf","version":{"version_data":[{"version_affected":">=","version_value":"0.2.26"},{"version_affected":"<=","version_value":"0.2.27"}]}}]},"vendor_name":"solana-labs"}]}},"credit":[{"lang":"eng","value":"BlockSec"}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In Solana rBPF versions 0.2.26 and 0.2.27 are affected by Incorrect Calculation which is caused by improper implementation of sdiv instruction. This can lead to the wrong execution path, resulting in huge loss in specific cases. For example, the result of a sdiv instruction may decide whether to transfer tokens or not. The vulnerability affects both integrity and may cause serious availability problems."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-682 Incorrect Calculation"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://github.com/solana-labs/rbpf/commit/e61e045f8c244de978401d186dcfd50838817297","name":"https://github.com/solana-labs/rbpf/commit/e61e045f8c244de978401d186dcfd50838817297"},{"refsource":"MISC","url":"https://www.whitesourcesoftware.com/vulnerability-database/CVE-2022-23066","name":"https://www.whitesourcesoftware.com/vulnerability-database/CVE-2022-23066"},{"refsource":"MISC","url":"https://blocksecteam.medium.com/how-a-critical-bug-in-solana-network-was-detected-and-timely-patched-a701870e1324","name":"https://blocksecteam.medium.com/how-a-critical-bug-in-solana-network-was-detected-and-timely-patched-a701870e1324"}]},"solution":[{"lang":"eng","value":"Upgrade version to 0.2.28 or higher"}],"source":{"advisory":"https://www.whitesourcesoftware.com/vulnerability-database/","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2022-05-09 07:15:00","lastModifiedDate":"2023-02-10 16:38:00","problem_types":["CWE-682"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.2},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.4},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:solana:rbpf:0.2.27:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:solana:rbpf:0.2.26:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2022","CveId":"23066","Ordinal":"225657","Title":"CVE-2022-23066","CVE":"CVE-2022-23066","Year":"2022"},"notes":[{"CveYear":"2022","CveId":"23066","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}