Lucene search

K
osvGoogleOSV:CVE-2021-46102
HistoryJan 27, 2022 - 6:15 p.m.

CVE-2021-46102

2022-01-2718:15:07
Google
osv.dev
4
cve-2021-46102
solana rbpf
integer overflow
src/elf.rs
elf file
security bug

AI Score

7.1

Confidence

High

EPSS

0.003

Percentile

68.7%

From version 0.2.14 to 0.2.16 for Solana rBPF, function “relocate” in the file src/elf.rs has an integer overflow bug because the sym.st_value is read directly from ELF file without checking. If the sym.st_value is rather large, an integer overflow is triggered while calculating the variable “addr” via “addr = (sym.st_value + refd_pa) as u64”;

AI Score

7.1

Confidence

High

EPSS

0.003

Percentile

68.7%

Related for OSV:CVE-2021-46102