CVE-2022-23066
Incorrect Calculation in solana_rbpf
9.1
CRITICAL
CVSS 3.1
EPSS 2.3%
Description
In Solana rBPF versions 0.2.26 and 0.2.27 are affected by Incorrect Calculation which is caused by improper implementation of sdiv instruction. This can lead to the wrong execution path, resulting in huge loss in specific cases. For example, the result of a sdiv instruction may decide whether to transfer tokens or not. The vulnerability affects both integrity and may cause serious availability problems.
How to fix CVE-2022-23066
To remediate CVE-2022-23066, upgrade the affected package to a fixed version below.
- —upgrade to 0.2.28 or later
Is CVE-2022-23066 being exploited?
Low — EPSS is 2.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 0.2.26, < 0.2.28
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |