PT-2026-8036 · Unknown · Ton Virtual Machine
Published
2026-02-13
·
Updated
2026-02-18
·
CVE-2025-70955
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
TON Virtual Machine versions prior to 2024.10
Description
A Stack Overflow issue exists in the TON Virtual Machine (TVM). The root cause is the improper handling of
vmstate and continuation jump instructions, leading to continuous dynamic tail calls. An attacker can exploit this by creating a smart contract with deeply nested jump logic. This nested execution exhausts the host process's stack space, even within permissible gas limits, resulting in a Denial of Service (DoS) for the TON blockchain network.Recommendations
Update to version 2024.10 or later.
Fix
DoS
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ton Virtual Machine