PT-2026-8035 · Unknown · Ton Virtual Machine+1

Published

2026-02-13

·

Updated

2026-02-14

·

CVE-2025-70954

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions TON Blockchain versions prior to 2025.06
Description A flaw exists in the TON Virtual Machine (TVM) within the TON Blockchain. The issue resides in the execution logic of the INMSGPARAM instruction, where the program does not validate if a pointer is null before accessing it. An attacker can trigger a null pointer dereference by sending a malicious transaction or smart contract. This can cause the validator node process to crash, resulting in a Denial of Service (DoS) and impacting the availability of the blockchain network.
Recommendations Update to version 2025.06 or later.

Exploit

Fix

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2025-70954

Affected Products

Ton Blockchain
Ton Virtual Machine