Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Solana Subscribe
Filtered by product Rbpf
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-23066 1 Solana 1 Rbpf 2023-02-10 6.4 MEDIUM 9.1 CRITICAL
In Solana rBPF versions 0.2.26 and 0.2.27 are affected by Incorrect Calculation which is caused by improper implementation of sdiv instruction. This can lead to the wrong execution path, resulting in huge loss in specific cases. For example, the result of a sdiv instruction may decide whether to transfer tokens or not. The vulnerability affects both integrity and may cause serious availability problems.
CVE-2022-31264 1 Solana 1 Rbpf 2022-06-02 5.0 MEDIUM 7.5 HIGH
Solana solana_rbpf before 0.2.29 has an addition integer overflow via invalid ELF program headers. elf.rs has a panic via a malformed eBPF program.
CVE-2021-46102 1 Solana 1 Rbpf 2022-02-07 5.0 MEDIUM 7.5 HIGH
From version 0.2.14 to 0.2.16 for Solana rBPF, function "relocate" in the file src/elf.rs has an integer overflow bug because the sym.st_value is read directly from ELF file without checking. If the sym.st_value is rather large, an integer overflow is triggered while calculating the variable "addr" via "addr = (sym.st_value + refd_pa) as u64";