PT-2025-18927 · Openvm · Openvm
Published
2025-05-02
·
Updated
2025-05-05
·
CVE-2025-46723
CVSS v2.0
9.4
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
OpenVM version 1.0.0
Description
The issue is related to an overflow vulnerability in the AUIPC instruction decomposition of the OpenVM framework. A typo in the code results in incorrect range checking of the highest limb of
pc, leading to a situation where a malicious prover can manipulate the destination register to take a different value than intended. This is achieved by making the decomposition overflow the BabyBear field.Recommendations
For OpenVM version 1.0.0, update to version 1.1.0 to resolve the issue. As a temporary workaround, consider restricting the use of the AUIPC instruction in the affected version until the patch is applied.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openvm