Search
Find a vulnerability
Search criteria
8 vulnerabilities by solanalabs
CVE-2024-30253 (GCVE-0-2024-30253)
Vulnerability from nvd – Published: 2024-04-17 15:07 – Updated: 2024-08-21 15:05
VLAI
EPSS
VEX
Title
Handling untrusted input can result in a crash, leading to loss of availability / denial of service
Summary
@solana/web3.js is the Solana JavaScript SDK. Using particular inputs with `@solana/web3.js` will result in memory exhaustion (OOM). If you have a server, client, mobile, or desktop product that accepts untrusted input for use with `@solana/web3.js`, your application/service may crash, resulting in a loss of availability. This vulnerability is fixed in 1.0.1, 1.10.2, 1.11.1, 1.12.1, 1.1.2, 1.13.1, 1.14.1, 1.15.1, 1.16.2, 1.17.1, 1.18.1, 1.19.1, 1.20.3, 1.21.1, 1.22.1, 1.23.1, 1.24.3, 1.25.1, 1.26.1, 1.27.1, 1.28.1, 1.2.8, 1.29.4, 1.30.3, 1.31.1, 1.3.1, 1.32.3, 1.33.1, 1.34.1, 1.35.2, 1.36.1, 1.37.3, 1.38.1, 1.39.2, 1.40.2, 1.41.11, 1.4.1, 1.42.1, 1.43.7, 1.44.4, 1.45.1, 1.46.1, 1.47.5, 1.48.1, 1.49.1, 1.50.2, 1.51.1, 1.5.1, 1.52.1, 1.53.1, 1.54.2, 1.55.1, 1.56.3, 1.57.1, 1.58.1, 1.59.2, 1.60.1, 1.61.2, 1.6.1, 1.62.2, 1.63.2, 1.64.1, 1.65.1, 1.66.6, 1.67.3, 1.68.2, 1.69.1, 1.70.4, 1.71.1, 1.72.1, 1.7.2, 1.73.5, 1.74.1, 1.75.1, 1.76.1, 1.77.4, 1.78.8, 1.79.1, 1.80.1, 1.81.1, 1.8.1, 1.82.1, 1.83.1, 1.84.1, 1.85.1, 1.86.1, 1.87.7, 1.88.1, 1.89.2, 1.90.2, 1.9.2, and 1.91.3.
Severity
7.5 (High)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-08-21 14:18 UTC
CWE
- CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/solana-labs/solana-web3.js/sec… | x_refsource_CONFIRM |
| https://github.com/solana-labs/solana-web3.js/com… | x_refsource_MISC |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| solana-labs | solana-web3.js |
Affected:
>= 1.91.0, < 1.91.3
Affected: >= 1.90, < 1.90.2 Affected: >= 1.89, < 1.89.2 Affected: = 1.88.0 Affected: >=1.87.0, < 1.87.7 Affected: = 1.86.0 Affected: = 1.85.0 Affected: = 1.84.0 Affected: = 1.83.0 Affected: = 1.82.0 Affected: = 1.81.0 Affected: = 1.80.0 Affected: = 1.79.0 Affected: >= 1.78, < 1.78.8 Affected: >= 1.77, < 1.77.4 Affected: = 1.76.0 Affected: = 1.75.0 Affected: = 1.74.0 Affected: >= 1.73.0, < 1.73.5 Affected: = 1.72.0 Affected: = 1.71.0 Affected: >= 1.70.0, < 1.70.4 Affected: = 1.69.0 Affected: >= 1.68.0, < 1.68.2 Affected: >= 1.67.0, < 1.67.3 Affected: >= 1.66.0, < 1.66.6 Affected: = 1.65.0 Affected: = 1.64.0 Affected: >= 1.63.0, < 1.63.2 Affected: >= 1.62.0, < 1.62.2 Affected: >= 1.61.0, < 1.61.2 Affected: = 1.60.0 Affected: >= 1.59.0, < 1.59.2 Affected: = 1.58.0 Affected: = 1.57.0 Affected: >= 1.56.0, < 1.56.3 Affected: = 1.55.0 Affected: >= 1.54.0, < 1.54.2 Affected: = 1.53.0 Affected: = 1.52.0 Affected: = 1.51.0 Affected: >= 1.50.0, < 1.50.2 Affected: = 1.49.0 Affected: = 1.48.0 Affected: >= 1.47.0, < 1.47.5 Affected: = 1.46.0 Affected: = 1.45.0 Affected: >= 1.44.0, < 1.44.4 Affected: >= 1.43.0, < 1.43.7 Affected: = 1.42.0 Affected: >= 1.41.0, < 1.41.11 Affected: >= 1.40.0, < 1.40.2 Affected: >= 1.39.0, < 1.39.2 Affected: = 1.38.0 Affected: >= 1.37.0, < 1.37.3 Affected: = 1.36.0 Affected: >= 1.35.0, < 1.35.2 Affected: = 1.34.0 Affected: = 1.33.0 Affected: >= 1.32.0, < 1.32.2 Affected: = 1.31.0 Affected: >= 1.30.0, < 1.30.3 Affected: >= 1.29.0, < 1.29.4 Affected: = 1.28.0 Affected: = 1.27.0 Affected: = 1.26.0 Affected: = 1.25.0 Affected: >= 1.24.0, < 1.24.3 Affected: = 1.23.0 Affected: = 1.22.0 Affected: = 1.21.0 Affected: >= 1.20.0, < 1.20.3 Affected: = 1.19.0 Affected: = 1.18.0 Affected: = 1.17.0 Affected: >= 1.16.0, < 1.16.2 Affected: = 1.15.0 Affected: = 1.14.0 Affected: = 1.13.0 Affected: = 1.12.0 Affected: = 1.11.0 Affected: >= 1.10.0, < 1.10.2 Affected: >= 1.9.0, < 1.9.2 Affected: = 1.8.0 Affected: >= 1.7.0, < 1.7.2 Affected: = 1.6.0 Affected: = 1.5.0 Affected: = 1.4.0 Affected: = 1.3.0 Affected: >= 1.2.0, < 1.2.8 Affected: >= 1.1.0, < 1.1.2 Affected: < 1.0.1 |
|
| solanalabs | web3 |
Affected:
1.91.0 , < 1.91.3
(custom)
Affected: 1.90 , < 1.90.2 (custom) Affected: 1.89 , < 1.89.2 (custom) Affected: 1.88.0 Affected: 1.87.0 , < 1.87.7 (custom) Affected: 1.86.0 Affected: 1.85.0 Affected: 1.84.0 Affected: 1.83.0 Affected: 1.82.0 Affected: 1.81.0 Affected: 1.80.0 Affected: 1.79.0 Affected: 1.78 , < 1.78.8 (custom) Affected: 1.77 , < 1.77.4 (custom) Affected: 1.76.0 Affected: 1.75.0 Affected: 1.74.0 Affected: 1.73.0 , < 1.73.5 (custom) Affected: 1.72.0 Affected: 1.71.0 Affected: 1.70.0 , < 1.70.4 (custom) Affected: 1.69.0 Affected: 1.68.0 , < 1.68.2 (custom) Affected: 1.67.0 , < 1.67.3 (custom) Affected: 1.66.0 , < 1.66.6 (custom) Affected: 1.65.0 Affected: 1.64.0 Affected: 1.63.0 , < 1.63.2 (custom) Affected: 1.62.0 , < 1.62.2 (custom) Affected: 1.61.0 , < 1.61.2 (custom) Affected: 1.60.0 Affected: 1.59.0 , < 1.59.2 (custom) Affected: 1.58.0 Affected: 1.57.0 Affected: 1.56.0 , < 1.56.3 (custom) Affected: 1.55.0 Affected: 1.54.0 , < 1.54.2 (custom) Affected: 1.53.0 Affected: 1.52.0 Affected: 1.51.0 Affected: 1.50.0 , < 1.50.2 (custom) Affected: 1.49.0 Affected: 1.48.0 Affected: 1.47.0 , < 1.47.5 (custom) Affected: 1.46.0 Affected: 1.45.0 Affected: 1.44.0 , < 1.44.4 (custom) Affected: 1.43.0 , < 1.43.7 (custom) Affected: 1.42.0 Affected: 1.41.0 , < 1.41.11 (custom) Affected: 1.40.0 , < 1.40.2 (custom) Affected: 1.39.0 , < 1.39.2 (custom) Affected: 1.38.0 Affected: 1.37.0 , < 1.37.3 (custom) Affected: 1.36.0 Affected: 1.35.0 , < 1.35.2 (custom) Affected: 1.34.0 Affected: 1.33.0 Affected: 1.32.0 , < 1.32.2 (custom) Affected: 1.31.0 Affected: 1.30.0 , < 1.30.3 (custom) Affected: 1.29.0 , < 1.29.4 (custom) Affected: 1.28.0 Affected: 1.27.0 Affected: 1.26.0 Affected: 1.25.0 Affected: 1.24.0 , < 1.24.3 (custom) Affected: 1.23.0 Affected: 1.22.0 Affected: 1.21.0 Affected: 1.20.0 , < 1.20.3 (custom) Affected: 1.19.0 Affected: 1.18.0 Affected: 1.17.0 Affected: 1.16.0 , < 1.16.2 (custom) Affected: 1.15.0 Affected: 1.14.0 Affected: 1.13.0 Affected: 1.12.0 Affected: 1.11.0 Affected: 1.10.0 , < 1.10.2 (custom) Affected: 1.9.0 , < 1.9.2 (custom) Affected: 1.8.0 Affected: 1.7.0 , < 1.7.2 (custom) Affected: 1.6.0 Affected: 1.5.0 Affected: 1.4.0 Affected: 1.3.0 Affected: 1.2.0 , < 1.2.8 (custom) Affected: 1.1.0 , < 1.1.2 (custom) Affected: 0 , < 1.0.1 (custom) cpe:2.3:a:solanalabs:web3:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T01:32:06.308Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "https://github.com/solana-labs/solana-web3.js/security/advisories/GHSA-8m45-2rjm-j347",
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "https://github.com/solana-labs/solana-web3.js/security/advisories/GHSA-8m45-2rjm-j347"
},
{
"name": "https://github.com/solana-labs/solana-web3.js/commit/77d935221a4805107b20b60ae7c1148725e4e2d0",
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/solana-labs/solana-web3.js/commit/77d935221a4805107b20b60ae7c1148725e4e2d0"
}
],
"title": "CVE Program Container"
},
{
"affected": [
{
"cpes": [
"cpe:2.3:a:solanalabs:web3:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "web3",
"vendor": "solanalabs",
"versions": [
{
"lessThan": "1.91.3",
"status": "affected",
"version": "1.91.0",
"versionType": "custom"
},
{
"lessThan": "1.90.2",
"status": "affected",
"version": "1.90",
"versionType": "custom"
},
{
"lessThan": "1.89.2",
"status": "affected",
"version": "1.89",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.88.0"
},
{
"lessThan": "1.87.7",
"status": "affected",
"version": "1.87.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.86.0"
},
{
"status": "affected",
"version": "1.85.0"
},
{
"status": "affected",
"version": "1.84.0"
},
{
"status": "affected",
"version": "1.83.0"
},
{
"status": "affected",
"version": "1.82.0"
},
{
"status": "affected",
"version": "1.81.0"
},
{
"status": "affected",
"version": "1.80.0"
},
{
"status": "affected",
"version": "1.79.0"
},
{
"lessThan": "1.78.8",
"status": "affected",
"version": "1.78",
"versionType": "custom"
},
{
"lessThan": "1.77.4",
"status": "affected",
"version": "1.77",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.76.0"
},
{
"status": "affected",
"version": "1.75.0"
},
{
"status": "affected",
"version": "1.74.0"
},
{
"lessThan": "1.73.5",
"status": "affected",
"version": "1.73.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.72.0"
},
{
"status": "affected",
"version": "1.71.0"
},
{
"lessThan": "1.70.4",
"status": "affected",
"version": "1.70.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.69.0"
},
{
"lessThan": "1.68.2",
"status": "affected",
"version": "1.68.0",
"versionType": "custom"
},
{
"lessThan": "1.67.3",
"status": "affected",
"version": "1.67.0",
"versionType": "custom"
},
{
"lessThan": "1.66.6",
"status": "affected",
"version": "1.66.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.65.0"
},
{
"status": "affected",
"version": "1.64.0"
},
{
"lessThan": "1.63.2",
"status": "affected",
"version": "1.63.0",
"versionType": "custom"
},
{
"lessThan": "1.62.2",
"status": "affected",
"version": "1.62.0",
"versionType": "custom"
},
{
"lessThan": "1.61.2",
"status": "affected",
"version": "1.61.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.60.0"
},
{
"lessThan": "1.59.2",
"status": "affected",
"version": "1.59.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.58.0"
},
{
"status": "affected",
"version": "1.57.0"
},
{
"lessThan": "1.56.3",
"status": "affected",
"version": "1.56.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.55.0"
},
{
"lessThan": "1.54.2",
"status": "affected",
"version": "1.54.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.53.0"
},
{
"status": "affected",
"version": "1.52.0"
},
{
"status": "affected",
"version": "1.51.0"
},
{
"lessThan": "1.50.2",
"status": "affected",
"version": "1.50.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.49.0"
},
{
"status": "affected",
"version": "1.48.0"
},
{
"lessThan": "1.47.5",
"status": "affected",
"version": "1.47.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.46.0"
},
{
"status": "affected",
"version": "1.45.0"
},
{
"lessThan": "1.44.4",
"status": "affected",
"version": "1.44.0",
"versionType": "custom"
},
{
"lessThan": "1.43.7",
"status": "affected",
"version": "1.43.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.42.0"
},
{
"lessThan": "1.41.11",
"status": "affected",
"version": "1.41.0",
"versionType": "custom"
},
{
"lessThan": "1.40.2",
"status": "affected",
"version": "1.40.0",
"versionType": "custom"
},
{
"lessThan": "1.39.2",
"status": "affected",
"version": "1.39.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.38.0"
},
{
"lessThan": "1.37.3",
"status": "affected",
"version": "1.37.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.36.0"
},
{
"lessThan": "1.35.2",
"status": "affected",
"version": "1.35.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.34.0"
},
{
"status": "affected",
"version": "1.33.0"
},
{
"lessThan": "1.32.2",
"status": "affected",
"version": "1.32.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.31.0"
},
{
"lessThan": "1.30.3",
"status": "affected",
"version": "1.30.0",
"versionType": "custom"
},
{
"lessThan": "1.29.4",
"status": "affected",
"version": "1.29.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.28.0"
},
{
"status": "affected",
"version": "1.27.0"
},
{
"status": "affected",
"version": "1.26.0"
},
{
"status": "affected",
"version": "1.25.0"
},
{
"lessThan": "1.24.3",
"status": "affected",
"version": "1.24.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.23.0"
},
{
"status": "affected",
"version": "1.22.0"
},
{
"status": "affected",
"version": "1.21.0"
},
{
"lessThan": "1.20.3",
"status": "affected",
"version": "1.20.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.19.0"
},
{
"status": "affected",
"version": "1.18.0"
},
{
"status": "affected",
"version": "1.17.0"
},
{
"lessThan": "1.16.2",
"status": "affected",
"version": "1.16.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.15.0"
},
{
"status": "affected",
"version": "1.14.0"
},
{
"status": "affected",
"version": "1.13.0"
},
{
"status": "affected",
"version": "1.12.0"
},
{
"status": "affected",
"version": "1.11.0"
},
{
"lessThan": "1.10.2",
"status": "affected",
"version": "1.10.0",
"versionType": "custom"
},
{
"lessThan": "1.9.2",
"status": "affected",
"version": "1.9.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.8.0"
},
{
"lessThan": "1.7.2",
"status": "affected",
"version": "1.7.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.6.0"
},
{
"status": "affected",
"version": "1.5.0"
},
{
"status": "affected",
"version": "1.4.0"
},
{
"status": "affected",
"version": "1.3.0"
},
{
"lessThan": "1.2.8",
"status": "affected",
"version": "1.2.0",
"versionType": "custom"
},
{
"lessThan": "1.1.2",
"status": "affected",
"version": "1.1.0",
"versionType": "custom"
},
{
"lessThan": "1.0.1",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-30253",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-08-21T14:18:35.271487Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-08-21T15:05:27.101Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "solana-web3.js",
"vendor": "solana-labs",
"versions": [
{
"status": "affected",
"version": "\u003e= 1.91.0, \u003c 1.91.3"
},
{
"status": "affected",
"version": "\u003e= 1.90, \u003c 1.90.2"
},
{
"status": "affected",
"version": "\u003e= 1.89, \u003c 1.89.2"
},
{
"status": "affected",
"version": "= 1.88.0"
},
{
"status": "affected",
"version": "\u003e=1.87.0, \u003c 1.87.7"
},
{
"status": "affected",
"version": "= 1.86.0"
},
{
"status": "affected",
"version": "= 1.85.0"
},
{
"status": "affected",
"version": "= 1.84.0"
},
{
"status": "affected",
"version": "= 1.83.0"
},
{
"status": "affected",
"version": "= 1.82.0"
},
{
"status": "affected",
"version": "= 1.81.0"
},
{
"status": "affected",
"version": "= 1.80.0"
},
{
"status": "affected",
"version": "= 1.79.0"
},
{
"status": "affected",
"version": "\u003e= 1.78, \u003c 1.78.8"
},
{
"status": "affected",
"version": "\u003e= 1.77, \u003c 1.77.4"
},
{
"status": "affected",
"version": "= 1.76.0"
},
{
"status": "affected",
"version": "= 1.75.0"
},
{
"status": "affected",
"version": "= 1.74.0"
},
{
"status": "affected",
"version": "\u003e= 1.73.0, \u003c 1.73.5"
},
{
"status": "affected",
"version": "= 1.72.0"
},
{
"status": "affected",
"version": "= 1.71.0"
},
{
"status": "affected",
"version": "\u003e= 1.70.0, \u003c 1.70.4"
},
{
"status": "affected",
"version": "= 1.69.0"
},
{
"status": "affected",
"version": "\u003e= 1.68.0, \u003c 1.68.2"
},
{
"status": "affected",
"version": "\u003e= 1.67.0, \u003c 1.67.3"
},
{
"status": "affected",
"version": "\u003e= 1.66.0, \u003c 1.66.6"
},
{
"status": "affected",
"version": "= 1.65.0"
},
{
"status": "affected",
"version": "= 1.64.0"
},
{
"status": "affected",
"version": "\u003e= 1.63.0, \u003c 1.63.2"
},
{
"status": "affected",
"version": "\u003e= 1.62.0, \u003c 1.62.2"
},
{
"status": "affected",
"version": "\u003e= 1.61.0, \u003c 1.61.2"
},
{
"status": "affected",
"version": "= 1.60.0"
},
{
"status": "affected",
"version": "\u003e= 1.59.0, \u003c 1.59.2"
},
{
"status": "affected",
"version": "= 1.58.0"
},
{
"status": "affected",
"version": "= 1.57.0"
},
{
"status": "affected",
"version": "\u003e= 1.56.0, \u003c 1.56.3"
},
{
"status": "affected",
"version": "= 1.55.0"
},
{
"status": "affected",
"version": "\u003e= 1.54.0, \u003c 1.54.2"
},
{
"status": "affected",
"version": "= 1.53.0"
},
{
"status": "affected",
"version": "= 1.52.0"
},
{
"status": "affected",
"version": "= 1.51.0"
},
{
"status": "affected",
"version": "\u003e= 1.50.0, \u003c 1.50.2"
},
{
"status": "affected",
"version": "= 1.49.0"
},
{
"status": "affected",
"version": "= 1.48.0"
},
{
"status": "affected",
"version": "\u003e= 1.47.0, \u003c 1.47.5"
},
{
"status": "affected",
"version": "= 1.46.0"
},
{
"status": "affected",
"version": "= 1.45.0"
},
{
"status": "affected",
"version": "\u003e= 1.44.0, \u003c 1.44.4"
},
{
"status": "affected",
"version": "\u003e= 1.43.0, \u003c 1.43.7"
},
{
"status": "affected",
"version": "= 1.42.0"
},
{
"status": "affected",
"version": "\u003e= 1.41.0, \u003c 1.41.11"
},
{
"status": "affected",
"version": "\u003e= 1.40.0, \u003c 1.40.2"
},
{
"status": "affected",
"version": "\u003e= 1.39.0, \u003c 1.39.2"
},
{
"status": "affected",
"version": "= 1.38.0"
},
{
"status": "affected",
"version": "\u003e= 1.37.0, \u003c 1.37.3"
},
{
"status": "affected",
"version": "= 1.36.0"
},
{
"status": "affected",
"version": "\u003e= 1.35.0, \u003c 1.35.2"
},
{
"status": "affected",
"version": "= 1.34.0"
},
{
"status": "affected",
"version": "= 1.33.0"
},
{
"status": "affected",
"version": "\u003e= 1.32.0, \u003c 1.32.2"
},
{
"status": "affected",
"version": "= 1.31.0"
},
{
"status": "affected",
"version": "\u003e= 1.30.0, \u003c 1.30.3"
},
{
"status": "affected",
"version": "\u003e= 1.29.0, \u003c 1.29.4"
},
{
"status": "affected",
"version": "= 1.28.0"
},
{
"status": "affected",
"version": "= 1.27.0"
},
{
"status": "affected",
"version": "= 1.26.0"
},
{
"status": "affected",
"version": "= 1.25.0"
},
{
"status": "affected",
"version": "\u003e= 1.24.0, \u003c 1.24.3"
},
{
"status": "affected",
"version": "= 1.23.0"
},
{
"status": "affected",
"version": "= 1.22.0"
},
{
"status": "affected",
"version": "= 1.21.0"
},
{
"status": "affected",
"version": "\u003e= 1.20.0, \u003c 1.20.3"
},
{
"status": "affected",
"version": "= 1.19.0"
},
{
"status": "affected",
"version": "= 1.18.0"
},
{
"status": "affected",
"version": "= 1.17.0"
},
{
"status": "affected",
"version": "\u003e= 1.16.0, \u003c 1.16.2"
},
{
"status": "affected",
"version": "= 1.15.0"
},
{
"status": "affected",
"version": "= 1.14.0"
},
{
"status": "affected",
"version": "= 1.13.0"
},
{
"status": "affected",
"version": "= 1.12.0"
},
{
"status": "affected",
"version": "= 1.11.0"
},
{
"status": "affected",
"version": "\u003e= 1.10.0, \u003c 1.10.2"
},
{
"status": "affected",
"version": " \u003e= 1.9.0, \u003c 1.9.2"
},
{
"status": "affected",
"version": "= 1.8.0"
},
{
"status": "affected",
"version": "\u003e= 1.7.0, \u003c 1.7.2"
},
{
"status": "affected",
"version": "= 1.6.0"
},
{
"status": "affected",
"version": "= 1.5.0"
},
{
"status": "affected",
"version": "= 1.4.0"
},
{
"status": "affected",
"version": "= 1.3.0"
},
{
"status": "affected",
"version": "\u003e= 1.2.0, \u003c 1.2.8"
},
{
"status": "affected",
"version": "\u003e= 1.1.0, \u003c 1.1.2"
},
{
"status": "affected",
"version": "\u003c 1.0.1"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "@solana/web3.js is the Solana JavaScript SDK. Using particular inputs with `@solana/web3.js` will result in memory exhaustion (OOM). If you have a server, client, mobile, or desktop product that accepts untrusted input for use with `@solana/web3.js`, your application/service may crash, resulting in a loss of availability. This vulnerability is fixed in 1.0.1, 1.10.2, 1.11.1, 1.12.1, 1.1.2, 1.13.1, 1.14.1, 1.15.1, 1.16.2, 1.17.1, 1.18.1, 1.19.1, 1.20.3, 1.21.1, 1.22.1, 1.23.1, 1.24.3, 1.25.1, 1.26.1, 1.27.1, 1.28.1, 1.2.8, 1.29.4, 1.30.3, 1.31.1, 1.3.1, 1.32.3, 1.33.1, 1.34.1, 1.35.2, 1.36.1, 1.37.3, 1.38.1, 1.39.2, 1.40.2, 1.41.11, 1.4.1, 1.42.1, 1.43.7, 1.44.4, 1.45.1, 1.46.1, 1.47.5, 1.48.1, 1.49.1, 1.50.2, 1.51.1, 1.5.1, 1.52.1, 1.53.1, 1.54.2, 1.55.1, 1.56.3, 1.57.1, 1.58.1, 1.59.2, 1.60.1, 1.61.2, 1.6.1, 1.62.2, 1.63.2, 1.64.1, 1.65.1, 1.66.6, 1.67.3, 1.68.2, 1.69.1, 1.70.4, 1.71.1, 1.72.1, 1.7.2, 1.73.5, 1.74.1, 1.75.1, 1.76.1, 1.77.4, 1.78.8, 1.79.1, 1.80.1, 1.81.1, 1.8.1, 1.82.1, 1.83.1, 1.84.1, 1.85.1, 1.86.1, 1.87.7, 1.88.1, 1.89.2, 1.90.2, 1.9.2, and 1.91.3."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-119",
"description": "CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-04-17T19:48:46.105Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/solana-labs/solana-web3.js/security/advisories/GHSA-8m45-2rjm-j347",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/solana-labs/solana-web3.js/security/advisories/GHSA-8m45-2rjm-j347"
},
{
"name": "https://github.com/solana-labs/solana-web3.js/commit/77d935221a4805107b20b60ae7c1148725e4e2d0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/solana-labs/solana-web3.js/commit/77d935221a4805107b20b60ae7c1148725e4e2d0"
}
],
"source": {
"advisory": "GHSA-8m45-2rjm-j347",
"discovery": "UNKNOWN"
},
"title": "Handling untrusted input can result in a crash, leading to loss of availability / denial of service"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2024-30253",
"datePublished": "2024-04-17T15:07:27.546Z",
"dateReserved": "2024-03-26T12:52:00.933Z",
"dateUpdated": "2024-08-21T15:05:27.101Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2022-35917 (GCVE-0-2022-35917)
Vulnerability from nvd – Published: 2022-08-01 21:10 – Updated: 2025-04-23 17:54
VLAI
EPSS
VEX
Title
Weakness in Transfer Validation Logic in @solana/pay
Summary
Solana Pay is a protocol and set of reference implementations that enable developers to incorporate decentralized payments into their apps and services. When a Solana Pay transaction is located using a reference key, it may be checked to represent a transfer of the desired amount to the recipient, using the supplied `validateTransfer` function. An edge case regarding this mechanism could cause the validation logic to validate multiple transfers. This issue has been patched as of version `0.2.1`. Users of the Solana Pay SDK should upgrade to it. There are no known workarounds for this issue.
Severity
5.3 (Medium)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-04-23 15:52 UTC
CWE
- CWE-670 - Always-Incorrect Control Flow Implementation
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://github.com/solana-labs/solana-pay/securit… | x_refsource_CONFIRM |
| https://github.com/solana-labs/solana-pay/commit/… | x_refsource_MISC |
| https://github.com/solana-labs/solana-pay/blob/ma… | x_refsource_MISC |
| https://github.com/solana-labs/solana-pay/blob/ma… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| solana-labs | solana-pay |
Affected:
< 0.2.1
|
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-03T09:51:58.604Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "https://github.com/solana-labs/solana-pay/security/advisories/GHSA-j47c-j42c-mwqq"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/solana-labs/solana-pay/commit/ac6ce0d0a81137700874a8bf5a7caac3be999fad"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/solana-labs/solana-pay/blob/master/SPEC.md#reference"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/solana-labs/solana-pay/blob/master/core/src/validateTransfer.ts"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2022-35917",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-04-23T15:52:35.047087Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-04-23T17:54:43.793Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "solana-pay",
"vendor": "solana-labs",
"versions": [
{
"status": "affected",
"version": "\u003c 0.2.1"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Solana Pay is a protocol and set of reference implementations that enable developers to incorporate decentralized payments into their apps and services. When a Solana Pay transaction is located using a reference key, it may be checked to represent a transfer of the desired amount to the recipient, using the supplied `validateTransfer` function. An edge case regarding this mechanism could cause the validation logic to validate multiple transfers. This issue has been patched as of version `0.2.1`. Users of the Solana Pay SDK should upgrade to it. There are no known workarounds for this issue."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-670",
"description": "CWE-670: Always-Incorrect Control Flow Implementation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2022-08-01T21:10:11.000Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/solana-labs/solana-pay/security/advisories/GHSA-j47c-j42c-mwqq"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/solana-labs/solana-pay/commit/ac6ce0d0a81137700874a8bf5a7caac3be999fad"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/solana-labs/solana-pay/blob/master/SPEC.md#reference"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/solana-labs/solana-pay/blob/master/core/src/validateTransfer.ts"
}
],
"source": {
"advisory": "GHSA-j47c-j42c-mwqq",
"discovery": "UNKNOWN"
},
"title": "Weakness in Transfer Validation Logic in @solana/pay",
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "security-advisories@github.com",
"ID": "CVE-2022-35917",
"STATE": "PUBLIC",
"TITLE": "Weakness in Transfer Validation Logic in @solana/pay"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "solana-pay",
"version": {
"version_data": [
{
"version_value": "\u003c 0.2.1"
}
]
}
}
]
},
"vendor_name": "solana-labs"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Solana Pay is a protocol and set of reference implementations that enable developers to incorporate decentralized payments into their apps and services. When a Solana Pay transaction is located using a reference key, it may be checked to represent a transfer of the desired amount to the recipient, using the supplied `validateTransfer` function. An edge case regarding this mechanism could cause the validation logic to validate multiple transfers. This issue has been patched as of version `0.2.1`. Users of the Solana Pay SDK should upgrade to it. There are no known workarounds for this issue."
}
]
},
"impact": {
"cvss": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-670: Always-Incorrect Control Flow Implementation"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://github.com/solana-labs/solana-pay/security/advisories/GHSA-j47c-j42c-mwqq",
"refsource": "CONFIRM",
"url": "https://github.com/solana-labs/solana-pay/security/advisories/GHSA-j47c-j42c-mwqq"
},
{
"name": "https://github.com/solana-labs/solana-pay/commit/ac6ce0d0a81137700874a8bf5a7caac3be999fad",
"refsource": "MISC",
"url": "https://github.com/solana-labs/solana-pay/commit/ac6ce0d0a81137700874a8bf5a7caac3be999fad"
},
{
"name": "https://github.com/solana-labs/solana-pay/blob/master/SPEC.md#reference",
"refsource": "MISC",
"url": "https://github.com/solana-labs/solana-pay/blob/master/SPEC.md#reference"
},
{
"name": "https://github.com/solana-labs/solana-pay/blob/master/core/src/validateTransfer.ts",
"refsource": "MISC",
"url": "https://github.com/solana-labs/solana-pay/blob/master/core/src/validateTransfer.ts"
}
]
},
"source": {
"advisory": "GHSA-j47c-j42c-mwqq",
"discovery": "UNKNOWN"
}
}
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2022-35917",
"datePublished": "2022-08-01T21:10:11.000Z",
"dateReserved": "2022-07-15T00:00:00.000Z",
"dateUpdated": "2025-04-23T17:54:43.793Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2022-31264 (GCVE-0-2022-31264)
Vulnerability from nvd – Published: 2022-05-21 20:04 – Updated: 2024-08-03 07:11
VLAI
EPSS
VEX
Summary
Solana solana_rbpf before 0.2.29 has an addition integer overflow via invalid ELF program headers. elf.rs has a panic via a malformed eBPF program.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/Ainevsia/CVE-Request/tree/main… | x_refsource_MISC |
| https://github.com/solana-labs/rbpf/releases/tag/… | x_refsource_MISC |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-03T07:11:39.885Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/Ainevsia/CVE-Request/tree/main/Solana/1"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/solana-labs/rbpf/releases/tag/v0.2.29"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Solana solana_rbpf before 0.2.29 has an addition integer overflow via invalid ELF program headers. elf.rs has a panic via a malformed eBPF program."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2022-05-21T20:04:50.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/Ainevsia/CVE-Request/tree/main/Solana/1"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/solana-labs/rbpf/releases/tag/v0.2.29"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2022-31264",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Solana solana_rbpf before 0.2.29 has an addition integer overflow via invalid ELF program headers. elf.rs has a panic via a malformed eBPF program."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://github.com/Ainevsia/CVE-Request/tree/main/Solana/1",
"refsource": "MISC",
"url": "https://github.com/Ainevsia/CVE-Request/tree/main/Solana/1"
},
{
"name": "https://github.com/solana-labs/rbpf/releases/tag/v0.2.29",
"refsource": "MISC",
"url": "https://github.com/solana-labs/rbpf/releases/tag/v0.2.29"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2022-31264",
"datePublished": "2022-05-21T20:04:50.000Z",
"dateReserved": "2022-05-21T00:00:00.000Z",
"dateUpdated": "2024-08-03T07:11:39.885Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2021-46102 (GCVE-0-2021-46102)
Vulnerability from nvd – Published: 2022-01-27 17:44 – Updated: 2024-08-04 05:02
VLAI
EPSS
VEX
Summary
From version 0.2.14 to 0.2.16 for Solana rBPF, function "relocate" in the file src/elf.rs has an integer overflow bug because the sym.st_value is read directly from ELF file without checking. If the sym.st_value is rather large, an integer overflow is triggered while calculating the variable "addr" via "addr = (sym.st_value + refd_pa) as u64";
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://blocksecteam.medium.com/new-integer-overf… | x_refsource_MISC |
| https://github.com/solana-labs/rbpf/blob/c1476485… | x_refsource_MISC |
| https://github.com/solana-labs/rbpf/pull/200 | x_refsource_MISC |
| https://github.com/solana-labs/rbpf/pull/236 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-04T05:02:10.272Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://blocksecteam.medium.com/new-integer-overflow-bug-discovered-in-solana-rbpf-7729717159ee"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/solana-labs/rbpf/blob/c14764850f0b83b58aa013248eaf6d65836c1218/src/elf.rs#L609-L630"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/solana-labs/rbpf/pull/200"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/solana-labs/rbpf/pull/236"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "From version 0.2.14 to 0.2.16 for Solana rBPF, function \"relocate\" in the file src/elf.rs has an integer overflow bug because the sym.st_value is read directly from ELF file without checking. If the sym.st_value is rather large, an integer overflow is triggered while calculating the variable \"addr\" via \"addr = (sym.st_value + refd_pa) as u64\";"
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2022-01-27T17:44:59.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"tags": [
"x_refsource_MISC"
],
"url": "https://blocksecteam.medium.com/new-integer-overflow-bug-discovered-in-solana-rbpf-7729717159ee"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/solana-labs/rbpf/blob/c14764850f0b83b58aa013248eaf6d65836c1218/src/elf.rs#L609-L630"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/solana-labs/rbpf/pull/200"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/solana-labs/rbpf/pull/236"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2021-46102",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "From version 0.2.14 to 0.2.16 for Solana rBPF, function \"relocate\" in the file src/elf.rs has an integer overflow bug because the sym.st_value is read directly from ELF file without checking. If the sym.st_value is rather large, an integer overflow is triggered while calculating the variable \"addr\" via \"addr = (sym.st_value + refd_pa) as u64\";"
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://blocksecteam.medium.com/new-integer-overflow-bug-discovered-in-solana-rbpf-7729717159ee",
"refsource": "MISC",
"url": "https://blocksecteam.medium.com/new-integer-overflow-bug-discovered-in-solana-rbpf-7729717159ee"
},
{
"name": "https://github.com/solana-labs/rbpf/blob/c14764850f0b83b58aa013248eaf6d65836c1218/src/elf.rs#L609-L630",
"refsource": "MISC",
"url": "https://github.com/solana-labs/rbpf/blob/c14764850f0b83b58aa013248eaf6d65836c1218/src/elf.rs#L609-L630"
},
{
"name": "https://github.com/solana-labs/rbpf/pull/200",
"refsource": "MISC",
"url": "https://github.com/solana-labs/rbpf/pull/200"
},
{
"name": "https://github.com/solana-labs/rbpf/pull/236",
"refsource": "MISC",
"url": "https://github.com/solana-labs/rbpf/pull/236"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2021-46102",
"datePublished": "2022-01-27T17:44:59.000Z",
"dateReserved": "2022-01-03T00:00:00.000Z",
"dateUpdated": "2024-08-04T05:02:10.272Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2024-30253 (GCVE-0-2024-30253)
Vulnerability from cvelistv5 – Published: 2024-04-17 15:07 – Updated: 2024-08-21 15:05
VLAI
EPSS
VEX
Title
Handling untrusted input can result in a crash, leading to loss of availability / denial of service
Summary
@solana/web3.js is the Solana JavaScript SDK. Using particular inputs with `@solana/web3.js` will result in memory exhaustion (OOM). If you have a server, client, mobile, or desktop product that accepts untrusted input for use with `@solana/web3.js`, your application/service may crash, resulting in a loss of availability. This vulnerability is fixed in 1.0.1, 1.10.2, 1.11.1, 1.12.1, 1.1.2, 1.13.1, 1.14.1, 1.15.1, 1.16.2, 1.17.1, 1.18.1, 1.19.1, 1.20.3, 1.21.1, 1.22.1, 1.23.1, 1.24.3, 1.25.1, 1.26.1, 1.27.1, 1.28.1, 1.2.8, 1.29.4, 1.30.3, 1.31.1, 1.3.1, 1.32.3, 1.33.1, 1.34.1, 1.35.2, 1.36.1, 1.37.3, 1.38.1, 1.39.2, 1.40.2, 1.41.11, 1.4.1, 1.42.1, 1.43.7, 1.44.4, 1.45.1, 1.46.1, 1.47.5, 1.48.1, 1.49.1, 1.50.2, 1.51.1, 1.5.1, 1.52.1, 1.53.1, 1.54.2, 1.55.1, 1.56.3, 1.57.1, 1.58.1, 1.59.2, 1.60.1, 1.61.2, 1.6.1, 1.62.2, 1.63.2, 1.64.1, 1.65.1, 1.66.6, 1.67.3, 1.68.2, 1.69.1, 1.70.4, 1.71.1, 1.72.1, 1.7.2, 1.73.5, 1.74.1, 1.75.1, 1.76.1, 1.77.4, 1.78.8, 1.79.1, 1.80.1, 1.81.1, 1.8.1, 1.82.1, 1.83.1, 1.84.1, 1.85.1, 1.86.1, 1.87.7, 1.88.1, 1.89.2, 1.90.2, 1.9.2, and 1.91.3.
Severity
7.5 (High)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-08-21 14:18 UTC
CWE
- CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/solana-labs/solana-web3.js/sec… | x_refsource_CONFIRM |
| https://github.com/solana-labs/solana-web3.js/com… | x_refsource_MISC |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| solana-labs | solana-web3.js |
Affected:
>= 1.91.0, < 1.91.3
Affected: >= 1.90, < 1.90.2 Affected: >= 1.89, < 1.89.2 Affected: = 1.88.0 Affected: >=1.87.0, < 1.87.7 Affected: = 1.86.0 Affected: = 1.85.0 Affected: = 1.84.0 Affected: = 1.83.0 Affected: = 1.82.0 Affected: = 1.81.0 Affected: = 1.80.0 Affected: = 1.79.0 Affected: >= 1.78, < 1.78.8 Affected: >= 1.77, < 1.77.4 Affected: = 1.76.0 Affected: = 1.75.0 Affected: = 1.74.0 Affected: >= 1.73.0, < 1.73.5 Affected: = 1.72.0 Affected: = 1.71.0 Affected: >= 1.70.0, < 1.70.4 Affected: = 1.69.0 Affected: >= 1.68.0, < 1.68.2 Affected: >= 1.67.0, < 1.67.3 Affected: >= 1.66.0, < 1.66.6 Affected: = 1.65.0 Affected: = 1.64.0 Affected: >= 1.63.0, < 1.63.2 Affected: >= 1.62.0, < 1.62.2 Affected: >= 1.61.0, < 1.61.2 Affected: = 1.60.0 Affected: >= 1.59.0, < 1.59.2 Affected: = 1.58.0 Affected: = 1.57.0 Affected: >= 1.56.0, < 1.56.3 Affected: = 1.55.0 Affected: >= 1.54.0, < 1.54.2 Affected: = 1.53.0 Affected: = 1.52.0 Affected: = 1.51.0 Affected: >= 1.50.0, < 1.50.2 Affected: = 1.49.0 Affected: = 1.48.0 Affected: >= 1.47.0, < 1.47.5 Affected: = 1.46.0 Affected: = 1.45.0 Affected: >= 1.44.0, < 1.44.4 Affected: >= 1.43.0, < 1.43.7 Affected: = 1.42.0 Affected: >= 1.41.0, < 1.41.11 Affected: >= 1.40.0, < 1.40.2 Affected: >= 1.39.0, < 1.39.2 Affected: = 1.38.0 Affected: >= 1.37.0, < 1.37.3 Affected: = 1.36.0 Affected: >= 1.35.0, < 1.35.2 Affected: = 1.34.0 Affected: = 1.33.0 Affected: >= 1.32.0, < 1.32.2 Affected: = 1.31.0 Affected: >= 1.30.0, < 1.30.3 Affected: >= 1.29.0, < 1.29.4 Affected: = 1.28.0 Affected: = 1.27.0 Affected: = 1.26.0 Affected: = 1.25.0 Affected: >= 1.24.0, < 1.24.3 Affected: = 1.23.0 Affected: = 1.22.0 Affected: = 1.21.0 Affected: >= 1.20.0, < 1.20.3 Affected: = 1.19.0 Affected: = 1.18.0 Affected: = 1.17.0 Affected: >= 1.16.0, < 1.16.2 Affected: = 1.15.0 Affected: = 1.14.0 Affected: = 1.13.0 Affected: = 1.12.0 Affected: = 1.11.0 Affected: >= 1.10.0, < 1.10.2 Affected: >= 1.9.0, < 1.9.2 Affected: = 1.8.0 Affected: >= 1.7.0, < 1.7.2 Affected: = 1.6.0 Affected: = 1.5.0 Affected: = 1.4.0 Affected: = 1.3.0 Affected: >= 1.2.0, < 1.2.8 Affected: >= 1.1.0, < 1.1.2 Affected: < 1.0.1 |
|
| solanalabs | web3 |
Affected:
1.91.0 , < 1.91.3
(custom)
Affected: 1.90 , < 1.90.2 (custom) Affected: 1.89 , < 1.89.2 (custom) Affected: 1.88.0 Affected: 1.87.0 , < 1.87.7 (custom) Affected: 1.86.0 Affected: 1.85.0 Affected: 1.84.0 Affected: 1.83.0 Affected: 1.82.0 Affected: 1.81.0 Affected: 1.80.0 Affected: 1.79.0 Affected: 1.78 , < 1.78.8 (custom) Affected: 1.77 , < 1.77.4 (custom) Affected: 1.76.0 Affected: 1.75.0 Affected: 1.74.0 Affected: 1.73.0 , < 1.73.5 (custom) Affected: 1.72.0 Affected: 1.71.0 Affected: 1.70.0 , < 1.70.4 (custom) Affected: 1.69.0 Affected: 1.68.0 , < 1.68.2 (custom) Affected: 1.67.0 , < 1.67.3 (custom) Affected: 1.66.0 , < 1.66.6 (custom) Affected: 1.65.0 Affected: 1.64.0 Affected: 1.63.0 , < 1.63.2 (custom) Affected: 1.62.0 , < 1.62.2 (custom) Affected: 1.61.0 , < 1.61.2 (custom) Affected: 1.60.0 Affected: 1.59.0 , < 1.59.2 (custom) Affected: 1.58.0 Affected: 1.57.0 Affected: 1.56.0 , < 1.56.3 (custom) Affected: 1.55.0 Affected: 1.54.0 , < 1.54.2 (custom) Affected: 1.53.0 Affected: 1.52.0 Affected: 1.51.0 Affected: 1.50.0 , < 1.50.2 (custom) Affected: 1.49.0 Affected: 1.48.0 Affected: 1.47.0 , < 1.47.5 (custom) Affected: 1.46.0 Affected: 1.45.0 Affected: 1.44.0 , < 1.44.4 (custom) Affected: 1.43.0 , < 1.43.7 (custom) Affected: 1.42.0 Affected: 1.41.0 , < 1.41.11 (custom) Affected: 1.40.0 , < 1.40.2 (custom) Affected: 1.39.0 , < 1.39.2 (custom) Affected: 1.38.0 Affected: 1.37.0 , < 1.37.3 (custom) Affected: 1.36.0 Affected: 1.35.0 , < 1.35.2 (custom) Affected: 1.34.0 Affected: 1.33.0 Affected: 1.32.0 , < 1.32.2 (custom) Affected: 1.31.0 Affected: 1.30.0 , < 1.30.3 (custom) Affected: 1.29.0 , < 1.29.4 (custom) Affected: 1.28.0 Affected: 1.27.0 Affected: 1.26.0 Affected: 1.25.0 Affected: 1.24.0 , < 1.24.3 (custom) Affected: 1.23.0 Affected: 1.22.0 Affected: 1.21.0 Affected: 1.20.0 , < 1.20.3 (custom) Affected: 1.19.0 Affected: 1.18.0 Affected: 1.17.0 Affected: 1.16.0 , < 1.16.2 (custom) Affected: 1.15.0 Affected: 1.14.0 Affected: 1.13.0 Affected: 1.12.0 Affected: 1.11.0 Affected: 1.10.0 , < 1.10.2 (custom) Affected: 1.9.0 , < 1.9.2 (custom) Affected: 1.8.0 Affected: 1.7.0 , < 1.7.2 (custom) Affected: 1.6.0 Affected: 1.5.0 Affected: 1.4.0 Affected: 1.3.0 Affected: 1.2.0 , < 1.2.8 (custom) Affected: 1.1.0 , < 1.1.2 (custom) Affected: 0 , < 1.0.1 (custom) cpe:2.3:a:solanalabs:web3:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T01:32:06.308Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "https://github.com/solana-labs/solana-web3.js/security/advisories/GHSA-8m45-2rjm-j347",
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "https://github.com/solana-labs/solana-web3.js/security/advisories/GHSA-8m45-2rjm-j347"
},
{
"name": "https://github.com/solana-labs/solana-web3.js/commit/77d935221a4805107b20b60ae7c1148725e4e2d0",
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/solana-labs/solana-web3.js/commit/77d935221a4805107b20b60ae7c1148725e4e2d0"
}
],
"title": "CVE Program Container"
},
{
"affected": [
{
"cpes": [
"cpe:2.3:a:solanalabs:web3:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "web3",
"vendor": "solanalabs",
"versions": [
{
"lessThan": "1.91.3",
"status": "affected",
"version": "1.91.0",
"versionType": "custom"
},
{
"lessThan": "1.90.2",
"status": "affected",
"version": "1.90",
"versionType": "custom"
},
{
"lessThan": "1.89.2",
"status": "affected",
"version": "1.89",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.88.0"
},
{
"lessThan": "1.87.7",
"status": "affected",
"version": "1.87.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.86.0"
},
{
"status": "affected",
"version": "1.85.0"
},
{
"status": "affected",
"version": "1.84.0"
},
{
"status": "affected",
"version": "1.83.0"
},
{
"status": "affected",
"version": "1.82.0"
},
{
"status": "affected",
"version": "1.81.0"
},
{
"status": "affected",
"version": "1.80.0"
},
{
"status": "affected",
"version": "1.79.0"
},
{
"lessThan": "1.78.8",
"status": "affected",
"version": "1.78",
"versionType": "custom"
},
{
"lessThan": "1.77.4",
"status": "affected",
"version": "1.77",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.76.0"
},
{
"status": "affected",
"version": "1.75.0"
},
{
"status": "affected",
"version": "1.74.0"
},
{
"lessThan": "1.73.5",
"status": "affected",
"version": "1.73.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.72.0"
},
{
"status": "affected",
"version": "1.71.0"
},
{
"lessThan": "1.70.4",
"status": "affected",
"version": "1.70.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.69.0"
},
{
"lessThan": "1.68.2",
"status": "affected",
"version": "1.68.0",
"versionType": "custom"
},
{
"lessThan": "1.67.3",
"status": "affected",
"version": "1.67.0",
"versionType": "custom"
},
{
"lessThan": "1.66.6",
"status": "affected",
"version": "1.66.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.65.0"
},
{
"status": "affected",
"version": "1.64.0"
},
{
"lessThan": "1.63.2",
"status": "affected",
"version": "1.63.0",
"versionType": "custom"
},
{
"lessThan": "1.62.2",
"status": "affected",
"version": "1.62.0",
"versionType": "custom"
},
{
"lessThan": "1.61.2",
"status": "affected",
"version": "1.61.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.60.0"
},
{
"lessThan": "1.59.2",
"status": "affected",
"version": "1.59.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.58.0"
},
{
"status": "affected",
"version": "1.57.0"
},
{
"lessThan": "1.56.3",
"status": "affected",
"version": "1.56.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.55.0"
},
{
"lessThan": "1.54.2",
"status": "affected",
"version": "1.54.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.53.0"
},
{
"status": "affected",
"version": "1.52.0"
},
{
"status": "affected",
"version": "1.51.0"
},
{
"lessThan": "1.50.2",
"status": "affected",
"version": "1.50.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.49.0"
},
{
"status": "affected",
"version": "1.48.0"
},
{
"lessThan": "1.47.5",
"status": "affected",
"version": "1.47.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.46.0"
},
{
"status": "affected",
"version": "1.45.0"
},
{
"lessThan": "1.44.4",
"status": "affected",
"version": "1.44.0",
"versionType": "custom"
},
{
"lessThan": "1.43.7",
"status": "affected",
"version": "1.43.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.42.0"
},
{
"lessThan": "1.41.11",
"status": "affected",
"version": "1.41.0",
"versionType": "custom"
},
{
"lessThan": "1.40.2",
"status": "affected",
"version": "1.40.0",
"versionType": "custom"
},
{
"lessThan": "1.39.2",
"status": "affected",
"version": "1.39.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.38.0"
},
{
"lessThan": "1.37.3",
"status": "affected",
"version": "1.37.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.36.0"
},
{
"lessThan": "1.35.2",
"status": "affected",
"version": "1.35.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.34.0"
},
{
"status": "affected",
"version": "1.33.0"
},
{
"lessThan": "1.32.2",
"status": "affected",
"version": "1.32.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.31.0"
},
{
"lessThan": "1.30.3",
"status": "affected",
"version": "1.30.0",
"versionType": "custom"
},
{
"lessThan": "1.29.4",
"status": "affected",
"version": "1.29.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.28.0"
},
{
"status": "affected",
"version": "1.27.0"
},
{
"status": "affected",
"version": "1.26.0"
},
{
"status": "affected",
"version": "1.25.0"
},
{
"lessThan": "1.24.3",
"status": "affected",
"version": "1.24.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.23.0"
},
{
"status": "affected",
"version": "1.22.0"
},
{
"status": "affected",
"version": "1.21.0"
},
{
"lessThan": "1.20.3",
"status": "affected",
"version": "1.20.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.19.0"
},
{
"status": "affected",
"version": "1.18.0"
},
{
"status": "affected",
"version": "1.17.0"
},
{
"lessThan": "1.16.2",
"status": "affected",
"version": "1.16.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.15.0"
},
{
"status": "affected",
"version": "1.14.0"
},
{
"status": "affected",
"version": "1.13.0"
},
{
"status": "affected",
"version": "1.12.0"
},
{
"status": "affected",
"version": "1.11.0"
},
{
"lessThan": "1.10.2",
"status": "affected",
"version": "1.10.0",
"versionType": "custom"
},
{
"lessThan": "1.9.2",
"status": "affected",
"version": "1.9.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.8.0"
},
{
"lessThan": "1.7.2",
"status": "affected",
"version": "1.7.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.6.0"
},
{
"status": "affected",
"version": "1.5.0"
},
{
"status": "affected",
"version": "1.4.0"
},
{
"status": "affected",
"version": "1.3.0"
},
{
"lessThan": "1.2.8",
"status": "affected",
"version": "1.2.0",
"versionType": "custom"
},
{
"lessThan": "1.1.2",
"status": "affected",
"version": "1.1.0",
"versionType": "custom"
},
{
"lessThan": "1.0.1",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-30253",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-08-21T14:18:35.271487Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-08-21T15:05:27.101Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "solana-web3.js",
"vendor": "solana-labs",
"versions": [
{
"status": "affected",
"version": "\u003e= 1.91.0, \u003c 1.91.3"
},
{
"status": "affected",
"version": "\u003e= 1.90, \u003c 1.90.2"
},
{
"status": "affected",
"version": "\u003e= 1.89, \u003c 1.89.2"
},
{
"status": "affected",
"version": "= 1.88.0"
},
{
"status": "affected",
"version": "\u003e=1.87.0, \u003c 1.87.7"
},
{
"status": "affected",
"version": "= 1.86.0"
},
{
"status": "affected",
"version": "= 1.85.0"
},
{
"status": "affected",
"version": "= 1.84.0"
},
{
"status": "affected",
"version": "= 1.83.0"
},
{
"status": "affected",
"version": "= 1.82.0"
},
{
"status": "affected",
"version": "= 1.81.0"
},
{
"status": "affected",
"version": "= 1.80.0"
},
{
"status": "affected",
"version": "= 1.79.0"
},
{
"status": "affected",
"version": "\u003e= 1.78, \u003c 1.78.8"
},
{
"status": "affected",
"version": "\u003e= 1.77, \u003c 1.77.4"
},
{
"status": "affected",
"version": "= 1.76.0"
},
{
"status": "affected",
"version": "= 1.75.0"
},
{
"status": "affected",
"version": "= 1.74.0"
},
{
"status": "affected",
"version": "\u003e= 1.73.0, \u003c 1.73.5"
},
{
"status": "affected",
"version": "= 1.72.0"
},
{
"status": "affected",
"version": "= 1.71.0"
},
{
"status": "affected",
"version": "\u003e= 1.70.0, \u003c 1.70.4"
},
{
"status": "affected",
"version": "= 1.69.0"
},
{
"status": "affected",
"version": "\u003e= 1.68.0, \u003c 1.68.2"
},
{
"status": "affected",
"version": "\u003e= 1.67.0, \u003c 1.67.3"
},
{
"status": "affected",
"version": "\u003e= 1.66.0, \u003c 1.66.6"
},
{
"status": "affected",
"version": "= 1.65.0"
},
{
"status": "affected",
"version": "= 1.64.0"
},
{
"status": "affected",
"version": "\u003e= 1.63.0, \u003c 1.63.2"
},
{
"status": "affected",
"version": "\u003e= 1.62.0, \u003c 1.62.2"
},
{
"status": "affected",
"version": "\u003e= 1.61.0, \u003c 1.61.2"
},
{
"status": "affected",
"version": "= 1.60.0"
},
{
"status": "affected",
"version": "\u003e= 1.59.0, \u003c 1.59.2"
},
{
"status": "affected",
"version": "= 1.58.0"
},
{
"status": "affected",
"version": "= 1.57.0"
},
{
"status": "affected",
"version": "\u003e= 1.56.0, \u003c 1.56.3"
},
{
"status": "affected",
"version": "= 1.55.0"
},
{
"status": "affected",
"version": "\u003e= 1.54.0, \u003c 1.54.2"
},
{
"status": "affected",
"version": "= 1.53.0"
},
{
"status": "affected",
"version": "= 1.52.0"
},
{
"status": "affected",
"version": "= 1.51.0"
},
{
"status": "affected",
"version": "\u003e= 1.50.0, \u003c 1.50.2"
},
{
"status": "affected",
"version": "= 1.49.0"
},
{
"status": "affected",
"version": "= 1.48.0"
},
{
"status": "affected",
"version": "\u003e= 1.47.0, \u003c 1.47.5"
},
{
"status": "affected",
"version": "= 1.46.0"
},
{
"status": "affected",
"version": "= 1.45.0"
},
{
"status": "affected",
"version": "\u003e= 1.44.0, \u003c 1.44.4"
},
{
"status": "affected",
"version": "\u003e= 1.43.0, \u003c 1.43.7"
},
{
"status": "affected",
"version": "= 1.42.0"
},
{
"status": "affected",
"version": "\u003e= 1.41.0, \u003c 1.41.11"
},
{
"status": "affected",
"version": "\u003e= 1.40.0, \u003c 1.40.2"
},
{
"status": "affected",
"version": "\u003e= 1.39.0, \u003c 1.39.2"
},
{
"status": "affected",
"version": "= 1.38.0"
},
{
"status": "affected",
"version": "\u003e= 1.37.0, \u003c 1.37.3"
},
{
"status": "affected",
"version": "= 1.36.0"
},
{
"status": "affected",
"version": "\u003e= 1.35.0, \u003c 1.35.2"
},
{
"status": "affected",
"version": "= 1.34.0"
},
{
"status": "affected",
"version": "= 1.33.0"
},
{
"status": "affected",
"version": "\u003e= 1.32.0, \u003c 1.32.2"
},
{
"status": "affected",
"version": "= 1.31.0"
},
{
"status": "affected",
"version": "\u003e= 1.30.0, \u003c 1.30.3"
},
{
"status": "affected",
"version": "\u003e= 1.29.0, \u003c 1.29.4"
},
{
"status": "affected",
"version": "= 1.28.0"
},
{
"status": "affected",
"version": "= 1.27.0"
},
{
"status": "affected",
"version": "= 1.26.0"
},
{
"status": "affected",
"version": "= 1.25.0"
},
{
"status": "affected",
"version": "\u003e= 1.24.0, \u003c 1.24.3"
},
{
"status": "affected",
"version": "= 1.23.0"
},
{
"status": "affected",
"version": "= 1.22.0"
},
{
"status": "affected",
"version": "= 1.21.0"
},
{
"status": "affected",
"version": "\u003e= 1.20.0, \u003c 1.20.3"
},
{
"status": "affected",
"version": "= 1.19.0"
},
{
"status": "affected",
"version": "= 1.18.0"
},
{
"status": "affected",
"version": "= 1.17.0"
},
{
"status": "affected",
"version": "\u003e= 1.16.0, \u003c 1.16.2"
},
{
"status": "affected",
"version": "= 1.15.0"
},
{
"status": "affected",
"version": "= 1.14.0"
},
{
"status": "affected",
"version": "= 1.13.0"
},
{
"status": "affected",
"version": "= 1.12.0"
},
{
"status": "affected",
"version": "= 1.11.0"
},
{
"status": "affected",
"version": "\u003e= 1.10.0, \u003c 1.10.2"
},
{
"status": "affected",
"version": " \u003e= 1.9.0, \u003c 1.9.2"
},
{
"status": "affected",
"version": "= 1.8.0"
},
{
"status": "affected",
"version": "\u003e= 1.7.0, \u003c 1.7.2"
},
{
"status": "affected",
"version": "= 1.6.0"
},
{
"status": "affected",
"version": "= 1.5.0"
},
{
"status": "affected",
"version": "= 1.4.0"
},
{
"status": "affected",
"version": "= 1.3.0"
},
{
"status": "affected",
"version": "\u003e= 1.2.0, \u003c 1.2.8"
},
{
"status": "affected",
"version": "\u003e= 1.1.0, \u003c 1.1.2"
},
{
"status": "affected",
"version": "\u003c 1.0.1"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "@solana/web3.js is the Solana JavaScript SDK. Using particular inputs with `@solana/web3.js` will result in memory exhaustion (OOM). If you have a server, client, mobile, or desktop product that accepts untrusted input for use with `@solana/web3.js`, your application/service may crash, resulting in a loss of availability. This vulnerability is fixed in 1.0.1, 1.10.2, 1.11.1, 1.12.1, 1.1.2, 1.13.1, 1.14.1, 1.15.1, 1.16.2, 1.17.1, 1.18.1, 1.19.1, 1.20.3, 1.21.1, 1.22.1, 1.23.1, 1.24.3, 1.25.1, 1.26.1, 1.27.1, 1.28.1, 1.2.8, 1.29.4, 1.30.3, 1.31.1, 1.3.1, 1.32.3, 1.33.1, 1.34.1, 1.35.2, 1.36.1, 1.37.3, 1.38.1, 1.39.2, 1.40.2, 1.41.11, 1.4.1, 1.42.1, 1.43.7, 1.44.4, 1.45.1, 1.46.1, 1.47.5, 1.48.1, 1.49.1, 1.50.2, 1.51.1, 1.5.1, 1.52.1, 1.53.1, 1.54.2, 1.55.1, 1.56.3, 1.57.1, 1.58.1, 1.59.2, 1.60.1, 1.61.2, 1.6.1, 1.62.2, 1.63.2, 1.64.1, 1.65.1, 1.66.6, 1.67.3, 1.68.2, 1.69.1, 1.70.4, 1.71.1, 1.72.1, 1.7.2, 1.73.5, 1.74.1, 1.75.1, 1.76.1, 1.77.4, 1.78.8, 1.79.1, 1.80.1, 1.81.1, 1.8.1, 1.82.1, 1.83.1, 1.84.1, 1.85.1, 1.86.1, 1.87.7, 1.88.1, 1.89.2, 1.90.2, 1.9.2, and 1.91.3."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-119",
"description": "CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-04-17T19:48:46.105Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/solana-labs/solana-web3.js/security/advisories/GHSA-8m45-2rjm-j347",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/solana-labs/solana-web3.js/security/advisories/GHSA-8m45-2rjm-j347"
},
{
"name": "https://github.com/solana-labs/solana-web3.js/commit/77d935221a4805107b20b60ae7c1148725e4e2d0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/solana-labs/solana-web3.js/commit/77d935221a4805107b20b60ae7c1148725e4e2d0"
}
],
"source": {
"advisory": "GHSA-8m45-2rjm-j347",
"discovery": "UNKNOWN"
},
"title": "Handling untrusted input can result in a crash, leading to loss of availability / denial of service"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2024-30253",
"datePublished": "2024-04-17T15:07:27.546Z",
"dateReserved": "2024-03-26T12:52:00.933Z",
"dateUpdated": "2024-08-21T15:05:27.101Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2022-35917 (GCVE-0-2022-35917)
Vulnerability from cvelistv5 – Published: 2022-08-01 21:10 – Updated: 2025-04-23 17:54
VLAI
EPSS
VEX
Title
Weakness in Transfer Validation Logic in @solana/pay
Summary
Solana Pay is a protocol and set of reference implementations that enable developers to incorporate decentralized payments into their apps and services. When a Solana Pay transaction is located using a reference key, it may be checked to represent a transfer of the desired amount to the recipient, using the supplied `validateTransfer` function. An edge case regarding this mechanism could cause the validation logic to validate multiple transfers. This issue has been patched as of version `0.2.1`. Users of the Solana Pay SDK should upgrade to it. There are no known workarounds for this issue.
Severity
5.3 (Medium)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-04-23 15:52 UTC
CWE
- CWE-670 - Always-Incorrect Control Flow Implementation
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://github.com/solana-labs/solana-pay/securit… | x_refsource_CONFIRM |
| https://github.com/solana-labs/solana-pay/commit/… | x_refsource_MISC |
| https://github.com/solana-labs/solana-pay/blob/ma… | x_refsource_MISC |
| https://github.com/solana-labs/solana-pay/blob/ma… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| solana-labs | solana-pay |
Affected:
< 0.2.1
|
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-03T09:51:58.604Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "https://github.com/solana-labs/solana-pay/security/advisories/GHSA-j47c-j42c-mwqq"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/solana-labs/solana-pay/commit/ac6ce0d0a81137700874a8bf5a7caac3be999fad"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/solana-labs/solana-pay/blob/master/SPEC.md#reference"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/solana-labs/solana-pay/blob/master/core/src/validateTransfer.ts"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2022-35917",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-04-23T15:52:35.047087Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-04-23T17:54:43.793Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "solana-pay",
"vendor": "solana-labs",
"versions": [
{
"status": "affected",
"version": "\u003c 0.2.1"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Solana Pay is a protocol and set of reference implementations that enable developers to incorporate decentralized payments into their apps and services. When a Solana Pay transaction is located using a reference key, it may be checked to represent a transfer of the desired amount to the recipient, using the supplied `validateTransfer` function. An edge case regarding this mechanism could cause the validation logic to validate multiple transfers. This issue has been patched as of version `0.2.1`. Users of the Solana Pay SDK should upgrade to it. There are no known workarounds for this issue."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-670",
"description": "CWE-670: Always-Incorrect Control Flow Implementation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2022-08-01T21:10:11.000Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/solana-labs/solana-pay/security/advisories/GHSA-j47c-j42c-mwqq"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/solana-labs/solana-pay/commit/ac6ce0d0a81137700874a8bf5a7caac3be999fad"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/solana-labs/solana-pay/blob/master/SPEC.md#reference"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/solana-labs/solana-pay/blob/master/core/src/validateTransfer.ts"
}
],
"source": {
"advisory": "GHSA-j47c-j42c-mwqq",
"discovery": "UNKNOWN"
},
"title": "Weakness in Transfer Validation Logic in @solana/pay",
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "security-advisories@github.com",
"ID": "CVE-2022-35917",
"STATE": "PUBLIC",
"TITLE": "Weakness in Transfer Validation Logic in @solana/pay"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "solana-pay",
"version": {
"version_data": [
{
"version_value": "\u003c 0.2.1"
}
]
}
}
]
},
"vendor_name": "solana-labs"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Solana Pay is a protocol and set of reference implementations that enable developers to incorporate decentralized payments into their apps and services. When a Solana Pay transaction is located using a reference key, it may be checked to represent a transfer of the desired amount to the recipient, using the supplied `validateTransfer` function. An edge case regarding this mechanism could cause the validation logic to validate multiple transfers. This issue has been patched as of version `0.2.1`. Users of the Solana Pay SDK should upgrade to it. There are no known workarounds for this issue."
}
]
},
"impact": {
"cvss": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-670: Always-Incorrect Control Flow Implementation"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://github.com/solana-labs/solana-pay/security/advisories/GHSA-j47c-j42c-mwqq",
"refsource": "CONFIRM",
"url": "https://github.com/solana-labs/solana-pay/security/advisories/GHSA-j47c-j42c-mwqq"
},
{
"name": "https://github.com/solana-labs/solana-pay/commit/ac6ce0d0a81137700874a8bf5a7caac3be999fad",
"refsource": "MISC",
"url": "https://github.com/solana-labs/solana-pay/commit/ac6ce0d0a81137700874a8bf5a7caac3be999fad"
},
{
"name": "https://github.com/solana-labs/solana-pay/blob/master/SPEC.md#reference",
"refsource": "MISC",
"url": "https://github.com/solana-labs/solana-pay/blob/master/SPEC.md#reference"
},
{
"name": "https://github.com/solana-labs/solana-pay/blob/master/core/src/validateTransfer.ts",
"refsource": "MISC",
"url": "https://github.com/solana-labs/solana-pay/blob/master/core/src/validateTransfer.ts"
}
]
},
"source": {
"advisory": "GHSA-j47c-j42c-mwqq",
"discovery": "UNKNOWN"
}
}
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2022-35917",
"datePublished": "2022-08-01T21:10:11.000Z",
"dateReserved": "2022-07-15T00:00:00.000Z",
"dateUpdated": "2025-04-23T17:54:43.793Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2022-31264 (GCVE-0-2022-31264)
Vulnerability from cvelistv5 – Published: 2022-05-21 20:04 – Updated: 2024-08-03 07:11
VLAI
EPSS
VEX
Summary
Solana solana_rbpf before 0.2.29 has an addition integer overflow via invalid ELF program headers. elf.rs has a panic via a malformed eBPF program.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/Ainevsia/CVE-Request/tree/main… | x_refsource_MISC |
| https://github.com/solana-labs/rbpf/releases/tag/… | x_refsource_MISC |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-03T07:11:39.885Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/Ainevsia/CVE-Request/tree/main/Solana/1"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/solana-labs/rbpf/releases/tag/v0.2.29"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Solana solana_rbpf before 0.2.29 has an addition integer overflow via invalid ELF program headers. elf.rs has a panic via a malformed eBPF program."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2022-05-21T20:04:50.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/Ainevsia/CVE-Request/tree/main/Solana/1"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/solana-labs/rbpf/releases/tag/v0.2.29"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2022-31264",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Solana solana_rbpf before 0.2.29 has an addition integer overflow via invalid ELF program headers. elf.rs has a panic via a malformed eBPF program."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://github.com/Ainevsia/CVE-Request/tree/main/Solana/1",
"refsource": "MISC",
"url": "https://github.com/Ainevsia/CVE-Request/tree/main/Solana/1"
},
{
"name": "https://github.com/solana-labs/rbpf/releases/tag/v0.2.29",
"refsource": "MISC",
"url": "https://github.com/solana-labs/rbpf/releases/tag/v0.2.29"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2022-31264",
"datePublished": "2022-05-21T20:04:50.000Z",
"dateReserved": "2022-05-21T00:00:00.000Z",
"dateUpdated": "2024-08-03T07:11:39.885Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2021-46102 (GCVE-0-2021-46102)
Vulnerability from cvelistv5 – Published: 2022-01-27 17:44 – Updated: 2024-08-04 05:02
VLAI
EPSS
VEX
Summary
From version 0.2.14 to 0.2.16 for Solana rBPF, function "relocate" in the file src/elf.rs has an integer overflow bug because the sym.st_value is read directly from ELF file without checking. If the sym.st_value is rather large, an integer overflow is triggered while calculating the variable "addr" via "addr = (sym.st_value + refd_pa) as u64";
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://blocksecteam.medium.com/new-integer-overf… | x_refsource_MISC |
| https://github.com/solana-labs/rbpf/blob/c1476485… | x_refsource_MISC |
| https://github.com/solana-labs/rbpf/pull/200 | x_refsource_MISC |
| https://github.com/solana-labs/rbpf/pull/236 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-04T05:02:10.272Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://blocksecteam.medium.com/new-integer-overflow-bug-discovered-in-solana-rbpf-7729717159ee"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/solana-labs/rbpf/blob/c14764850f0b83b58aa013248eaf6d65836c1218/src/elf.rs#L609-L630"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/solana-labs/rbpf/pull/200"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/solana-labs/rbpf/pull/236"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "From version 0.2.14 to 0.2.16 for Solana rBPF, function \"relocate\" in the file src/elf.rs has an integer overflow bug because the sym.st_value is read directly from ELF file without checking. If the sym.st_value is rather large, an integer overflow is triggered while calculating the variable \"addr\" via \"addr = (sym.st_value + refd_pa) as u64\";"
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2022-01-27T17:44:59.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"tags": [
"x_refsource_MISC"
],
"url": "https://blocksecteam.medium.com/new-integer-overflow-bug-discovered-in-solana-rbpf-7729717159ee"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/solana-labs/rbpf/blob/c14764850f0b83b58aa013248eaf6d65836c1218/src/elf.rs#L609-L630"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/solana-labs/rbpf/pull/200"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/solana-labs/rbpf/pull/236"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2021-46102",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "From version 0.2.14 to 0.2.16 for Solana rBPF, function \"relocate\" in the file src/elf.rs has an integer overflow bug because the sym.st_value is read directly from ELF file without checking. If the sym.st_value is rather large, an integer overflow is triggered while calculating the variable \"addr\" via \"addr = (sym.st_value + refd_pa) as u64\";"
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://blocksecteam.medium.com/new-integer-overflow-bug-discovered-in-solana-rbpf-7729717159ee",
"refsource": "MISC",
"url": "https://blocksecteam.medium.com/new-integer-overflow-bug-discovered-in-solana-rbpf-7729717159ee"
},
{
"name": "https://github.com/solana-labs/rbpf/blob/c14764850f0b83b58aa013248eaf6d65836c1218/src/elf.rs#L609-L630",
"refsource": "MISC",
"url": "https://github.com/solana-labs/rbpf/blob/c14764850f0b83b58aa013248eaf6d65836c1218/src/elf.rs#L609-L630"
},
{
"name": "https://github.com/solana-labs/rbpf/pull/200",
"refsource": "MISC",
"url": "https://github.com/solana-labs/rbpf/pull/200"
},
{
"name": "https://github.com/solana-labs/rbpf/pull/236",
"refsource": "MISC",
"url": "https://github.com/solana-labs/rbpf/pull/236"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2021-46102",
"datePublished": "2022-01-27T17:44:59.000Z",
"dateReserved": "2022-01-03T00:00:00.000Z",
"dateUpdated": "2024-08-04T05:02:10.272Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}