CVE-2022-23066
In Solana rBPF versions 0.2.26 and 0.2.27 are affected by Incorrect Calculation which is caused by improper implementation of sdiv instruction. This can lead to the wrong execution path, resulting in huge loss in specific cases. For example, the result of a sdiv instruction may decide whether to transfer tokens or not. The vulnerability affects both integrity and may cause serious availability problems.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- EPSS probability
- 1.12%
- CWE
- CWE-682
- Published
- 2022-05-09
- Last modified
- 2026-03-13
Affected products
- solana-labs rbpf
- solana-labs rbpf
Weakness type
Related vulnerabilities
- CVE-2023-2163 — Incorrect Verifier Branch Pruning Logic Leads To Arbitrary Read/Write In Linux Kernel and Lateral Privilege Escalation
- CVE-2021-31440 — This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.11.15. An a
- CVE-2023-2423 — Rockwell Automation Armor PowerFlex Vulnerable to Denial-Of-Service
- CVE-2026-54754 — Klever-Go: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped)
- CVE-2026-25634 — iccDEV memcpy-param-overlap in CIccTagMultiProcessElement::Apply()
- CVE-2026-53671 — PREVAIL: Context-write no-op in do_mem_store allows unsafe eBPF programs to pass verification
- CVE-2026-53670 — PREVAIL: Non-singleton typeset in add() skips offset update, allowing OOB access to pass eBPF verification
- CVE-2026-44498 — ZEBRA: Block Validator Undercounts Coinbase and P2SH Sigops