Lucene search

K
cvelistMitreCVELIST:CVE-2021-46102
HistoryJan 27, 2022 - 5:44 p.m.

CVE-2021-46102

2022-01-2717:44:59
mitre
www.cve.org
2
solana rbpf
integer overflow
relocate function
elf file
cve-2021-46102

EPSS

0.003

Percentile

68.7%

From version 0.2.14 to 0.2.16 for Solana rBPF, function “relocate” in the file src/elf.rs has an integer overflow bug because the sym.st_value is read directly from ELF file without checking. If the sym.st_value is rather large, an integer overflow is triggered while calculating the variable “addr” via “addr = (sym.st_value + refd_pa) as u64”;

EPSS

0.003

Percentile

68.7%

Related for CVELIST:CVE-2021-46102