[UPDATE] Turns out I was wrong and this is not a vulnerability at all:
https://crypto.stackexchange.com/questions/48580/fixed-point...