PT-2025-13411 · Tough · Tough

Adamkorcz

+1

·

Published

2025-03-27

·

Updated

2025-03-29

·

CVE-2025-2888

CVSS v4.0

5.7

Medium

VectorAV:N/AC:H/AT:N/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions tough versions prior to 0.20.0
Description The issue arises during a snapshot rollback when the client incorrectly caches the timestamp metadata. This leads to a failure in update timestamp validation, preventing further updates until the cache is cleared. The problem occurs because the client will persist invalid timestamp metadata to its cache, which may then cause it to incorrectly identify valid timestamp metadata as being rolled back. This prevents the client from consuming valid updates.
Recommendations For versions prior to 0.20.0, upgrade to tough version 0.20.0 or later and ensure any forked or derivative code is patched to incorporate the new fixes.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-2888
GHSA-76G3-38JV-WXH4

Affected Products

Tough