Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9qmm-4mfr-r3wj

Опубликовано: 10 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

Incorrect Calculation in solana_rbpf

In Solana rBPF versions 0.2.26 and 0.2.27 are affected by Incorrect Calculation which is caused by improper implementation of sdiv instruction. This can lead to the wrong execution path, resulting in huge loss in specific cases. For example, the result of a sdiv instruction may decide whether to transfer tokens or not. The vulnerability affects both integrity and may cause serious availability problems.

Пакеты

Наименование

solana_rbpf

rust
Затронутые версииВерсия исправления

>= 0.2.26, < 0.2.28

0.2.28

EPSS

Процентиль: 78%
0.01129
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-682

Связанные уязвимости

CVSS3: 9.1
nvd
больше 3 лет назад

In Solana rBPF versions 0.2.26 and 0.2.27 are affected by Incorrect Calculation which is caused by improper implementation of sdiv instruction. This can lead to the wrong execution path, resulting in huge loss in specific cases. For example, the result of a sdiv instruction may decide whether to transfer tokens or not. The vulnerability affects both integrity and may cause serious availability problems.

EPSS

Процентиль: 78%
0.01129
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-682