CVE-2025-2888 Details
Description
During a snapshot rollback, the client incorrectly caches the timestamp metadata. If the client checks the cache when attempting to perform the next update, the update timestamp validation will fail, preventing the next update until the cache is cleared. Users should upgrade to tough version 0.20.0 or later and ensure any forked or derivative code is patched to incorporate the new fixes.
A vulnerability exists in the Tough library, specifically in versions prior to 0.20.0, related to the incorrect caching of timestamp metadata during snapshot rollback events. This issue can cause the client to improperly validate update timestamps, leading to a failure in processing valid updates until the cache is manually cleared. The vulnerability arises because Tough, while it can detect rollbacks, still retains outdated timestamp metadata as trusted, which can disrupt the update process.
Users are advised to upgrade to Tough version 0.20.0 or later and to patch any forked or derivative code to include the latest fixes.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://aws.amazon.com/security/security-bulletins/AWS-2025-007/ | AMZN | Vendor Advisory |
| https://github.com/awslabs/tough/releases/tag/tough-v0.20.0 | AMZN | |
| https://github.com/awslabs/tough/security/advisories/GHSA-76g3-38jv-wxh4 | AMZN | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1025 | Comparison Using Wrong Factors | AMZN |
Affected Products
| Product | Versions |
|---|---|
| amazon tough | < 0.20.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | AMZN |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 14, 2025 | CVE Modified | AMZN |
| Sep 19, 2025 | Initial Analysis | [email protected] |
| Mar 27, 2025 | New CVE Received | AMZN |