PT-2026-8035 · Unknown · Ton Virtual Machine+1
Published
2026-02-13
·
Updated
2026-02-14
·
CVE-2025-70954
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
TON Blockchain versions prior to 2025.06
Description
A flaw exists in the TON Virtual Machine (TVM) within the TON Blockchain. The issue resides in the execution logic of the INMSGPARAM instruction, where the program does not validate if a pointer is null before accessing it. An attacker can trigger a null pointer dereference by sending a malicious transaction or smart contract. This can cause the validator node process to crash, resulting in a Denial of Service (DoS) and impacting the availability of the blockchain network.
Recommendations
Update to version 2025.06 or later.
Exploit
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ton Blockchain
Ton Virtual Machine