Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-24783

Опубликовано: 27 янв. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

soroban-fixed-point-math is a fixed-point math library for Soroban smart contacts. In versions 1.3.0 and 1.4.0, the mulDiv(x, y, z) function incorrectly handled cases where both the intermediate product $x * y$ and the divisor $z$ were negative. The logic assumed that if the intermediate product was negative, the final result must also be negative, neglecting the sign of $z$. This resulted in rounding being applied in the wrong direction for cases where both $x * y$ and $z$ were negative. The functions most at risk are fixed_div_floor and fixed_div_ceil, as they often use non-constant numbers as the divisor $z$ in mulDiv. This error is present in all signed FixedPoint and SorobanFixedPoint implementations, including i64, i128, and I256. Versions 1.3.1 and 1.4.1 contain a patch. No known workarounds for this issue are available.

EPSS

Процентиль: 1%
0.00012
Низкий

7.5 High

CVSS3

Дефекты

CWE-682

Связанные уязвимости

CVSS3: 7.5
github
10 дней назад

soroban-fixed-point-math has Incorrect Rounding and Overflow Handling in Signed Fixed-Point Math with Negatives

EPSS

Процентиль: 1%
0.00012
Низкий

7.5 High

CVSS3

Дефекты

CWE-682