cvedb.io
CVE-2022-23066
CRITICAL · CVSS 9.1
EPSS exploitation probability: 0%
Published 2022-05-09T07:15:08.330 · Last modified 2026-06-17T04:29:26.900

Summary

In Solana rBPF versions 0.2.26 and 0.2.27 are affected by Incorrect Calculation which is caused by improper implementation of sdiv instruction. This can lead to the wrong execution path, resulting in huge loss in specific cases. For example, the result of a sdiv instruction may decide whether to transfer tokens or not. The vulnerability affects both integrity and may cause serious availability problems.

Affected products

solana — rbpf

Does this affect you?

Add your gear to cvedb and we'll alert you only when solana ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.