PT-2026-8035 · Unknown · Ton Virtual Machine+1

CVE-2025-70954

·

Published

2026-02-13

·

Updated

2026-02-14

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions TON Blockchain versions prior to 2025.06
Description A flaw exists in the TON Virtual Machine (TVM) within the TON Blockchain. The issue resides in the execution logic of the INMSGPARAM instruction, where the program does not validate if a pointer is null before accessing it. An attacker can trigger a null pointer dereference by sending a malicious transaction or smart contract. This can cause the validator node process to crash, resulting in a Denial of Service (DoS) and impacting the availability of the blockchain network.
Recommendations Update to version 2025.06 or later.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-70954

Affected Products

Ton Blockchain
Ton Virtual Machine