Lucene search

K
osvGoogleOSV:GHSA-XWQR-XMGG-J69Q
HistoryJan 28, 2022 - 10:59 p.m.

Integer overflow in solana_rbpf

2022-01-2822:59:28
Google
osv.dev
10
solana rbpf
integer overflow
relocate function
elf file
version 0.2.14-0.2.16

EPSS

0.003

Percentile

68.7%

From version 0.2.14 to 0.2.16 for Solana rBPF, function “relocate” in the file src/elf.rs has an integer overflow bug because the sym.st_value is read directly from ELF file without checking. If the sym.st_value is rather large, an integer overflow is triggered while calculating the variable “addr” via addr = (sym.st_value + refd_pa) as u64

EPSS

0.003

Percentile

68.7%

Related for OSV:GHSA-XWQR-XMGG-J69Q