Описание
From version 0.2.14 to 0.2.16 for Solana rBPF, function "relocate" in the file src/elf.rs has an integer overflow bug because the sym.st_value is read directly from ELF file without checking. If the sym.st_value is rather large, an integer overflow is triggered while calculating the variable "addr" via "addr = (sym.st_value + refd_pa) as u64";
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 0.2.14 (включая) до 0.2.16 (включая)
cpe:2.3:a:solanalabs:rbpf:*:*:*:*:*:*:*:*
EPSS
Процентиль: 66%
0.00528
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-190
Связанные уязвимости
EPSS
Процентиль: 66%
0.00528
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-190